VYPR

CP900L

by Totolink

CVEs (8)

  • CVE-2024-35398CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules.

  • CVE-2024-35396CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.

  • CVE-2024-35397HigMay 28, 2024
    risk 0.58cvss 8.8epss 0.15

    TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2024-35399HigMay 28, 2024
    risk 0.57cvss 8.8epss 0.00

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth

  • CVE-2024-35395HigMay 24, 2024
    risk 0.57cvss 8.8epss 0.00

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

  • CVE-2024-35401MedMay 28, 2024
    risk 0.38cvss 5.9epss 0.01

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

  • CVE-2024-35400MedMay 28, 2024
    risk 0.34cvss 5.3epss 0.00

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules

  • CVE-2024-35403LowMay 28, 2024
    risk 0.18cvss 2.7epss 0.00

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRules