Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 2.1% | — | Totolink X6000rAI | 6/10/2026 | 6/10/2026 | A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed… | |
| Analizada | Alta (8.6) | 5.3% | — | Totolink X6000r Firmware | 23/3/2026 | 17/6/2026 | A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely. | |
| Analizada | Alta (8.8) | 1.8% | — | Totolink X6000r Firmware | 23/2/2026 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to a date -s shell command through CsteSystem. While the first two tokens of the input are validated,… | |
| Aplazada | Crítica (9.2) | 1.0% | — | Totolink X6000rAI | 30/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1498_B20250826. | |
| Analizada | Crítica (9.3) | 1.3% | — | Totolink X6000r Firmware | 25/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708. | |
| Analizada | Alta (7.3) | 0.85% | — | Totolink X6000r Firmware | 24/9/2025 | 17/6/2026 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207. | |
| Analizada | Crítica (9.3) | 13% | — | Totolink X6000r Firmware | 24/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207. | |
| Analizada | Alta (7) | 8.1% | — | Totolink X6000r Firmware | 23/9/2025 | 17/6/2026 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207. | |
| Analizada | Crítica (9.8) | 4.4% | — | Totolink X6000r Firmware | 15/9/2025 | 17/6/2026 | TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request. | |
| Modificada | Media (6.5) | 2.3% | — | Totolink X6000r Firmware | 29/7/2025 | 17/6/2026 | Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request. | |
| Analizada | Media (5.1) | 0.18% | — | Totolink X6000r Firmware | 11/2/2025 | 17/6/2026 | Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands. | |
| Modificada | Crítica (9.8) | 1.0% | — | Totolink X6000r Firmware | 22/11/2024 | 5/7/2026 | In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload. | |
| Analizada | Media (5.3) | 6.2% | — | Totolink X6000r Firmware | 18/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument rtLogServer leads to command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 4.0% | — | Totolink X6000r Firmware | 10/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation of the argument ip leads to os command injection. The attack may be initiated remotely.… | |
| Analizada | Crítica (9.8) | 15% | — | Totolink X6000r Firmware | 23/2/2024 | 17/6/2026 | A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (5.5) | 0.32% | — | Totolink X6000r Firmware | 20/2/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerability is an unknown functionality of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the local host. The complexity of an attack is… | |
| Modificada | Crítica (9.8) | 0.85% | — | Totolink X6000r Firmware | 24/1/2024 | 17/6/2026 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function. | |
| Modificada | Crítica (9.8) | 0.77% | — | Totolink X6000r Firmware | 24/1/2024 | 17/6/2026 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function. | |
| Modificada | Crítica (9.8) | 0.77% | — | Totolink X6000r Firmware | 24/1/2024 | 17/6/2026 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function. | |
| Modificada | Crítica (9.8) | 0.95% | — | Totolink X6000r Firmware | 16/1/2024 | 17/6/2026 | An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter. | |
| Modificada | Crítica (9.8) | 0.86% | — | Totolink X6000r Firmware | 16/1/2024 | 17/6/2026 | An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program. | |
| Modificada | Crítica (9.8) | 2.8% | — | Totolink X6000r Firmware | 30/12/2023 | 9/7/2026 | TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi. | |
| Modificada | Crítica (9.8) | 1.6% | — | Totolink X6000r Firmware | 4/12/2023 | 17/6/2026 | In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.4% | — | Totolink X6000r Firmware | 4/12/2023 | 17/6/2026 | TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution. | |
| Modificada | Crítica (9.8) | 1.7% | — | Totolink X6000r Firmware | 1/12/2023 | 17/6/2026 | In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability. |