6.9

CVSS4.0

CVE-2025-3674 - TOTOLINK A3700R cstecgi.cgi setUrlFilterRules access control

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched remotely. The explo…

πŸ“… Published: April 16, 2025, 7 a.m. πŸ”„ Last Modified: April 22, 2025, 4:52 p.m.

4.8

CVSS3.1

CVE-2024-10680 - Form Maker by 10Web < 1.15.32 - Admin+ Stored XSS

The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: April 16, 2025, 6 a.m. πŸ”„ Last Modified: April 23, 2025, 4:21 p.m.

5.3

CVSS3.1

CVE-2025-3247 - Contact Form 7 <= 6.0.5 - Order Replay Vulnerability

The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_check' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe Pa…

πŸ“… Published: April 16, 2025, 5:23 a.m. πŸ”„ Last Modified: April 8, 2026, 4:46 p.m.

6.9

CVSS4.0

CVE-2025-3668 - TOTOLINK A3700R cstecgi.cgi setScheduleCfg access control

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has be…

πŸ“… Published: April 16, 2025, 4:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:49 p.m.

6.9

CVSS4.0

CVE-2025-3667 - TOTOLINK A3700R cstecgi.cgi setUPnPCfg access control

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been dis…

πŸ“… Published: April 16, 2025, 4:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:49 p.m.

6.9

CVSS4.0

CVE-2025-3666 - TOTOLINK A3700R cstecgi.cgi setDdnsCfg access control

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed …

πŸ“… Published: April 16, 2025, 3:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:49 p.m.

9.8

CVSS3.1

CVE-2025-3495 - COMMGR - Insufficient Randomization Authentication Bypass

Delta Electronics COMMGR v1 and v2Β uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.

πŸ“… Published: April 16, 2025, 3:10 a.m. πŸ”„ Last Modified: Aug. 19, 2025, 12:11 a.m.

6.9

CVSS4.0

CVE-2025-3665 - TOTOLINK A3700R cstecgi.cgi setSmartQosCfg access control

A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit ha…

πŸ“… Published: April 16, 2025, 3 a.m. πŸ”„ Last Modified: April 22, 2025, 4:54 p.m.

6.9

CVSS4.0

CVE-2025-3664 - TOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg access control

A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has bee…

πŸ“… Published: April 16, 2025, 3 a.m. πŸ”„ Last Modified: April 22, 2025, 4:53 p.m.

6.9

CVSS4.0

CVE-2025-3663 - TOTOLINK A3700R Password cstecgi.cgi setWiFiEasyGuestCfg access control

A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component Password Handler. The manipulation leads to improper access controls. The …

πŸ“… Published: April 16, 2025, 2:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:50 p.m.
Total resulsts: 343924
Page 5256 of 34,393
Β« previous page Β» next page
Filters