VYPR

Vendor CVEs

Totolink

All CVEs

1,253 total · sorted by risk
  • CVE-2025-70329HigFeb 23, 2026
    risk 0.52cvss 8.0epss 0.03

    TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without…

  • CVE-2025-57579HigSep 12, 2025
    risk 0.52cvss 8.0epss 0.01

    An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password

  • CVE-2025-57578HigSep 12, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password

  • CVE-2025-57577HigSep 12, 2025
    risk 0.52cvss 8.0epss 0.01

    An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a…

  • CVE-2025-25635HigFeb 28, 2025
    risk 0.52cvss 8.0epss 0.00

    TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.

  • CVE-2025-25610HigFeb 28, 2025
    risk 0.52cvss 8.0epss 0.00

    TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.

  • CVE-2025-25609HigFeb 28, 2025
    risk 0.52cvss 8.0epss 0.00

    TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa

  • CVE-2024-57211HigJan 10, 2025
    risk 0.52cvss 8.0epss 0.01

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.

  • CVE-2024-41317HigJul 22, 2024
    risk 0.52cvss 8.0epss 0.02

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

  • CVE-2024-32355HigMay 14, 2024
    risk 0.52cvss 8.0epss 0.02

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.

  • CVE-2024-31811HigApr 8, 2024
    risk 0.52cvss 8.0epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.

  • CVE-2024-27521HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail,…

  • CVE-2024-28404HigMar 15, 2024
    risk 0.52cvss 8.0epss 0.00

    TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.

  • CVE-2024-28338HigMar 12, 2024
    risk 0.52cvss 8.0epss 0.01

    A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.

  • CVE-2023-7208HigJan 7, 2024
    risk 0.52cvss 8.0epss 0.02

    A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects the function formTmultiAP of the file /bin/boa. The manipulation leads to buffer overflow. VDB-249742 is the identifier assigned to this vulnerability. NOTE:…

  • CVE-2024-53335HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.

  • CVE-2024-51141HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

  • CVE-2024-42736HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.02

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.

  • CVE-2023-48192HigNov 20, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.

  • CVE-2022-38511HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.

  • CVE-2022-36616HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36615HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36614HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36613HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36612HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36611HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36610HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-37084HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the sPort parameter at the addEffect function.

  • CVE-2022-37083HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function setDiagnosisCfg.

  • CVE-2022-37082HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the function NTPSyncWithHost.

  • CVE-2022-37081HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.

  • CVE-2022-37080HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command parameter at setting/setTracerouteCfg.

  • CVE-2022-37079HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

  • CVE-2022-37078HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at /setting/setLanguageCfg.

  • CVE-2022-37077HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser parameter.

  • CVE-2022-36455HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

  • CVE-2022-37076HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

  • CVE-2022-37075HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.

  • CVE-2022-36488HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.

  • CVE-2022-36487HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36486HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

  • CVE-2022-36485HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

  • CVE-2022-36484HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the function setDiagnosisCfg.

  • CVE-2022-36483HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the pppoeUser parameter.

  • CVE-2022-36482HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the lang parameter in the function setLanguageCfg.

  • CVE-2022-36481HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg.

  • CVE-2022-36480HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36479HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

  • CVE-2022-36466HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.

  • CVE-2022-36465HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.

Page 17 of 26