Vendor CVEs
Totolink
All CVEs
1,425 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44260 | Hig | 0.57 | 8.8 | 0.02 | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function. | ||
| CVE-2022-44259 | Hig | 0.57 | 8.8 | 0.02 | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function. | ||
| CVE-2022-44258 | Hig | 0.57 | 8.8 | 0.02 | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function. | ||
| CVE-2022-44257 | Hig | 0.57 | 8.8 | 0.02 | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function. | ||
| CVE-2022-44256 | Hig | 0.57 | 8.8 | 0.02 | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function. | ||
| CVE-2022-44254 | Hig | 0.57 | 8.8 | 0.02 | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function. | ||
| CVE-2022-44253 | Hig | 0.57 | 8.8 | 0.02 | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function. | ||
| CVE-2022-41528 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function. | ||
| CVE-2022-41527 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function. | ||
| CVE-2022-41526 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg function. | ||
| CVE-2022-41524 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function. | ||
| CVE-2022-41523 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function. | ||
| CVE-2022-41521 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function. | ||
| CVE-2022-41520 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function. | ||
| CVE-2022-41517 | Hig | 0.57 | 8.8 | 0.01 | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function | ||
| CVE-2021-46010 | Hig | 0.57 | 8.8 | 0.01 | Mar 30, 2022 | Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations. | ||
| CVE-2021-46008 | Hig | 0.57 | 8.8 | 0.01 | Mar 30, 2022 | In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on. | ||
| CVE-2024-31813 | Hig | 0.55 | 8.4 | 0.00 | Apr 8, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default. | ||
| CVE-2026-79912 | Hig | 0.54 | 8.3 | 0.01 | Aug 25, 2026 | A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely.… | ||
| CVE-2024-57036 | Hig | 0.53 | 8.1 | 0.01 | Jan 21, 2025 | TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request. | ||
| CVE-2024-8580 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2024 | A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can be initiated remotely. The complexity of an… | ||
| CVE-2024-31817 | Hig | 0.53 | 7.5 | 0.55 | Apr 8, 2024 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg. | ||
| CVE-2022-29639 | Hig | 0.53 | 8.1 | 0.02 | May 18, 2022 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a command injection vulnerability via the magicid parameter in the function uci_cloudupdate_config. | ||
| CVE-2021-43664 | Hig | 0.53 | 8.1 | 0.02 | Mar 30, 2022 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo. | ||
| CVE-2025-70329 | Hig | 0.52 | 8.0 | 0.03 | Feb 23, 2026 | TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without… | ||
| CVE-2025-57579 | Hig | 0.52 | 8.0 | 0.01 | Sep 12, 2025 | An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password | ||
| CVE-2025-57578 | Hig | 0.52 | 8.0 | 0.00 | Sep 12, 2025 | An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password | ||
| CVE-2025-57577 | Hig | 0.52 | 8.0 | 0.01 | Sep 12, 2025 | An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a… | ||
| CVE-2025-25635 | Hig | 0.52 | 8.0 | 0.00 | Feb 28, 2025 | TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa. | ||
| CVE-2025-25610 | Hig | 0.52 | 8.0 | 0.00 | Feb 28, 2025 | TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa. | ||
| CVE-2025-25609 | Hig | 0.52 | 8.0 | 0.00 | Feb 28, 2025 | TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa | ||
| CVE-2024-57211 | Hig | 0.52 | 8.0 | 0.01 | Jan 10, 2025 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function. | ||
| CVE-2024-41317 | Hig | 0.52 | 8.0 | 0.02 | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function. | ||
| CVE-2024-32355 | Hig | 0.52 | 8.0 | 0.02 | May 14, 2024 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function. | ||
| CVE-2024-31811 | Hig | 0.52 | 8.0 | 0.01 | Apr 8, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function. | ||
| CVE-2024-27521 | Hig | 0.52 | 8.0 | 0.01 | Mar 26, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail,… | ||
| CVE-2024-28404 | Hig | 0.52 | 8.0 | 0.00 | Mar 15, 2024 | TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page. | ||
| CVE-2024-28338 | Hig | 0.52 | 8.0 | 0.01 | Mar 12, 2024 | A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie. | ||
| CVE-2023-7208 | Hig | 0.52 | 8.0 | 0.02 | Jan 7, 2024 | A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects the function formTmultiAP of the file /bin/boa. The manipulation leads to buffer overflow. VDB-249742 is the identifier assigned to this vulnerability. NOTE:… | ||
| CVE-2024-53335 | Hig | 0.51 | 7.8 | 0.00 | Nov 21, 2024 | TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi. | ||
| CVE-2024-51141 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2024 | An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components. | ||
| CVE-2024-42736 | Hig | 0.51 | 7.8 | 0.02 | Aug 13, 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands. | ||
| CVE-2023-48192 | Hig | 0.51 | 7.8 | 0.00 | Nov 20, 2023 | An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function. | ||
| CVE-2022-38511 | Hig | 0.51 | 7.8 | 0.01 | Aug 29, 2022 | TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi. | ||
| CVE-2022-36616 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36615 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36614 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36613 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36612 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36611 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample. |
- risk 0.57cvss 8.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.
- risk 0.57cvss 8.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.
- risk 0.57cvss 8.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.
- risk 0.57cvss 8.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.
- risk 0.57cvss 8.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.
- risk 0.57cvss 8.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.
- risk 0.57cvss 8.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
- risk 0.57cvss 8.8epss 0.01
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function
- risk 0.57cvss 8.8epss 0.01
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
- risk 0.57cvss 8.8epss 0.01
In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.
- risk 0.55cvss 8.4epss 0.00
TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.
- risk 0.54cvss 8.3epss 0.01
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely.…
- risk 0.53cvss 8.1epss 0.01
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.
- risk 0.53cvss 8.1epss 0.01
A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can be initiated remotely. The complexity of an…
- risk 0.53cvss 7.5epss 0.55
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
- risk 0.53cvss 8.1epss 0.02
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a command injection vulnerability via the magicid parameter in the function uci_cloudupdate_config.
- risk 0.53cvss 8.1epss 0.02
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.
- risk 0.52cvss 8.0epss 0.03
TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without…
- risk 0.52cvss 8.0epss 0.01
An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password
- risk 0.52cvss 8.0epss 0.00
An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password
- risk 0.52cvss 8.0epss 0.01
An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a…
- risk 0.52cvss 8.0epss 0.00
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.
- risk 0.52cvss 8.0epss 0.00
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.
- risk 0.52cvss 8.0epss 0.00
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa
- risk 0.52cvss 8.0epss 0.01
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.
- risk 0.52cvss 8.0epss 0.02
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
- risk 0.52cvss 8.0epss 0.02
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.
- risk 0.52cvss 8.0epss 0.01
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.
- risk 0.52cvss 8.0epss 0.01
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail,…
- risk 0.52cvss 8.0epss 0.00
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.
- risk 0.52cvss 8.0epss 0.01
A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.
- risk 0.52cvss 8.0epss 0.02
A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects the function formTmultiAP of the file /bin/boa. The manipulation leads to buffer overflow. VDB-249742 is the identifier assigned to this vulnerability. NOTE:…
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.
- risk 0.51cvss 7.8epss 0.00
An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.
- risk 0.51cvss 7.8epss 0.02
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
- risk 0.51cvss 7.8epss 0.00
An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.
- risk 0.51cvss 7.8epss 0.01
TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Page 18 of 29