VYPR

Vendor CVEs

Totolink

All CVEs

1,253 total · sorted by risk
  • CVE-2021-45740CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the pin parameter.

  • CVE-2021-45738CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.

  • CVE-2021-45733CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.

  • CVE-2021-44247CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom…

  • CVE-2021-35327CriAug 5, 2021
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.

  • CVE-2021-27710CriApr 14, 2021
    risk 0.64cvss 9.8epss 0.08

    Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes…

  • CVE-2021-27708CriApr 14, 2021
    risk 0.64cvss 9.8epss 0.08

    Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes…

  • CVE-2015-9551CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd sysCmd parameter.

  • CVE-2018-13316CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter.

  • CVE-2018-13314CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.

  • CVE-2018-13307CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.

  • CVE-2018-13306CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.

  • CVE-2018-13315CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.02

    Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.

  • CVE-2018-13311CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.

  • CVE-2017-1000020CriJul 17, 2017
    risk 0.64cvss 9.8epss 0.03

    SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devices, while sending SYN Flood or FIN Flood packets fails to validate and handle the packets and does…

  • CVE-2025-34319CriDec 3, 2025
    risk 0.61cvss epss 0.04

    TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vulnerability in the Boa formWsc handling functionality. An unauthenticated attacker can send specially crafted requests to trigger…

  • CVE-2025-52089HigJul 11, 2025
    risk 0.61cvss 8.8epss 0.07

    A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands with root privileges.

  • CVE-2026-1723CriJan 30, 2026
    risk 0.60cvss epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1498_B20250826.

  • CVE-2025-55895CriDec 15, 2025
    risk 0.59cvss 9.1epss 0.00

    TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).

  • CVE-2024-31815CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.01

    In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

  • CVE-2022-46025CriJan 10, 2024
    risk 0.59cvss 9.1epss 0.01

    Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi password, without logging into the management page.

  • CVE-2019-19824HigJan 27, 2020
    risk 0.59cvss 8.8epss 0.25

    On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects…

  • CVE-2025-8140HigJul 25, 2025
    risk 0.58cvss 8.8epss 0.07

    A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formWlanMultipleAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to…

  • CVE-2025-8138HigJul 25, 2025
    risk 0.58cvss 8.8epss 0.07

    A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formOneKeyAccessButton of the component HTTP POST Request Handler. The manipulation of the argument submit-url…

  • CVE-2025-5907HigJun 10, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack can be…

  • CVE-2025-5905HigJun 10, 2025
    risk 0.58cvss 8.8epss 0.09

    A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument Password leads to buffer…

  • CVE-2025-5904HigJun 10, 2025
    risk 0.58cvss 8.8epss 0.09

    A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument device_name leads to…

  • CVE-2025-5903HigJun 10, 2025
    risk 0.58cvss 8.8epss 0.09

    A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is…

  • CVE-2025-5902HigJun 9, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument slaveIpList leads to buffer overflow. The…

  • CVE-2025-5901HigJun 9, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument File leads to buffer…

  • CVE-2025-5792HigJun 6, 2025
    risk 0.58cvss 8.8epss 0.04

    A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of the argument redirect-url…

  • CVE-2025-5790HigJun 6, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. This vulnerability affects unknown code of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can…

  • CVE-2025-5788HigJun 6, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url…

  • CVE-2025-5787HigJun 6, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads…

  • CVE-2025-5786HigJun 6, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is…

  • CVE-2025-5785HigJun 6, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer…

  • CVE-2025-5739HigJun 6, 2025
    risk 0.58cvss 8.8epss 0.05

    A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is…

  • CVE-2025-2097HigMar 7, 2025
    risk 0.58cvss 8.8epss 0.07

    A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue affects the function setRptWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument loginpass leads to stack-based buffer overflow. The…

  • CVE-2025-1340HigFeb 16, 2025
    risk 0.58cvss 8.8epss 0.17

    A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation as part of String leads to stack-based buffer overflow. It is possible to launch the attack…

  • CVE-2024-7463HigAug 5, 2024
    risk 0.58cvss 8.8epss 0.11

    A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The…

  • CVE-2024-7157HigJul 28, 2024
    risk 0.58cvss 8.8epss 0.07

    A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been classified as critical. This affects the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_host leads to buffer overflow. It is…

  • CVE-2024-35397HigMay 28, 2024
    risk 0.58cvss 8.8epss 0.15

    TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2024-34921HigMay 14, 2024
    risk 0.58cvss 8.8epss 0.09

    TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.

  • CVE-2024-34219HigMay 14, 2024
    risk 0.58cvss 8.6epss 0.21

    TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

  • CVE-2024-31814HigApr 8, 2024
    risk 0.58cvss 8.8epss 0.09

    TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.

  • CVE-2024-2353HigMar 10, 2024
    risk 0.58cvss 8.8epss 0.04

    A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation of the argument ip leads to os command injection.…

  • CVE-2022-25008HigMar 30, 2022
    risk 0.58cvss 8.8epss 0.04

    totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.

  • CVE-2020-25499HigDec 9, 2020
    risk 0.58cvss 8.8epss 0.04

    TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.

  • CVE-2026-19847HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be…

  • CVE-2026-19846HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be…

Page 11 of 26