VYPR

Nr1800x Firmware

by Totolink

CVEs (27)

  • CVE-2022-41517HigOct 6, 2022
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

  • CVE-2025-60688MedNov 13, 2025
    risk 0.42cvss 6.5epss 0.01

    A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads the "IpAddress" parameter from a web request and copies…

  • CVE-2025-60684MedNov 13, 2025
    risk 0.42cvss 6.5epss 0.01

    A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings…

  • CVE-2026-5030MedMar 29, 2026
    risk 0.41cvss 6.3epss 0.02

    A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection. The attack can be…

  • CVE-2026-1327MedJan 22, 2026
    risk 0.41cvss 6.3epss 0.03

    A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Such manipulation of the argument command leads to command injection.…

  • CVE-2026-1326MedJan 22, 2026
    risk 0.41cvss 6.3epss 0.03

    A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument Hostname causes command injection. The attack can…

  • CVE-2025-60686MedNov 13, 2025
    risk 0.33cvss 5.1epss 0.00

    A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using…

Page 2 of 2