VYPR

Vendor CVEs

Totolink

All CVEs

1,425 total · sorted by risk
  • CVE-2022-44260HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.

  • CVE-2022-44259HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.

  • CVE-2022-44258HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.

  • CVE-2022-44257HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.

  • CVE-2022-44256HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.

  • CVE-2022-44254HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.

  • CVE-2022-44253HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.

  • CVE-2022-41528HigOct 6, 2022
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.

  • CVE-2022-41527HigOct 6, 2022
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.

  • CVE-2022-41526HigOct 6, 2022
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg function.

  • CVE-2022-41524HigOct 6, 2022
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.

  • CVE-2022-41523HigOct 6, 2022
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function.

  • CVE-2022-41521HigOct 6, 2022
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function.

  • CVE-2022-41520HigOct 6, 2022
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.

  • CVE-2022-41517HigOct 6, 2022
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

  • CVE-2021-46010HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.

  • CVE-2021-46008HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.01

    In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.

  • CVE-2024-31813HigApr 8, 2024
    risk 0.55cvss 8.4epss 0.00

    TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.

  • CVE-2026-79912HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.01

    A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely.…

  • CVE-2024-57036HigJan 21, 2025
    risk 0.53cvss 8.1epss 0.01

    TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.

  • CVE-2024-8580HigSep 8, 2024
    risk 0.53cvss 8.1epss 0.01

    A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can be initiated remotely. The complexity of an…

  • CVE-2024-31817HigApr 8, 2024
    risk 0.53cvss 7.5epss 0.55

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.

  • CVE-2022-29639HigMay 18, 2022
    risk 0.53cvss 8.1epss 0.02

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a command injection vulnerability via the magicid parameter in the function uci_cloudupdate_config.

  • CVE-2021-43664HigMar 30, 2022
    risk 0.53cvss 8.1epss 0.02

    totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.

  • CVE-2025-70329HigFeb 23, 2026
    risk 0.52cvss 8.0epss 0.03

    TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without…

  • CVE-2025-57579HigSep 12, 2025
    risk 0.52cvss 8.0epss 0.01

    An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password

  • CVE-2025-57578HigSep 12, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password

  • CVE-2025-57577HigSep 12, 2025
    risk 0.52cvss 8.0epss 0.01

    An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a…

  • CVE-2025-25635HigFeb 28, 2025
    risk 0.52cvss 8.0epss 0.00

    TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.

  • CVE-2025-25610HigFeb 28, 2025
    risk 0.52cvss 8.0epss 0.00

    TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.

  • CVE-2025-25609HigFeb 28, 2025
    risk 0.52cvss 8.0epss 0.00

    TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa

  • CVE-2024-57211HigJan 10, 2025
    risk 0.52cvss 8.0epss 0.01

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.

  • CVE-2024-41317HigJul 22, 2024
    risk 0.52cvss 8.0epss 0.02

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

  • CVE-2024-32355HigMay 14, 2024
    risk 0.52cvss 8.0epss 0.02

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.

  • CVE-2024-31811HigApr 8, 2024
    risk 0.52cvss 8.0epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.

  • CVE-2024-27521HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail,…

  • CVE-2024-28404HigMar 15, 2024
    risk 0.52cvss 8.0epss 0.00

    TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.

  • CVE-2024-28338HigMar 12, 2024
    risk 0.52cvss 8.0epss 0.01

    A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.

  • CVE-2023-7208HigJan 7, 2024
    risk 0.52cvss 8.0epss 0.02

    A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects the function formTmultiAP of the file /bin/boa. The manipulation leads to buffer overflow. VDB-249742 is the identifier assigned to this vulnerability. NOTE:…

  • CVE-2024-53335HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.

  • CVE-2024-51141HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

  • CVE-2024-42736HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.02

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.

  • CVE-2023-48192HigNov 20, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.

  • CVE-2022-38511HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.

  • CVE-2022-36616HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36615HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36614HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36613HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36612HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36611HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

Page 18 of 29