VYPR

Vendor CVEs

Totolink

All CVEs

1,253 total · sorted by risk
  • CVE-2022-36464HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.

  • CVE-2022-36463HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36462HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.

  • CVE-2022-36461HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

  • CVE-2022-36460HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

  • CVE-2022-36459HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

  • CVE-2022-36458HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36456HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

  • CVE-2024-34217HigMay 14, 2024
    risk 0.50cvss 7.7epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.

  • CVE-2024-28640HigMar 16, 2024
    risk 0.50cvss 7.5epss 0.14

    Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.

  • CVE-2021-35325HigAug 5, 2021
    risk 0.50cvss 7.5epss 0.13

    A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).

  • CVE-2026-36837HigApr 29, 2026
    risk 0.49cvss 7.5epss 0.00

    TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname parameter in the formMapDelDevice function.

  • CVE-2025-67445HigFeb 24, 2026
    risk 0.49cvss 7.5epss 0.00

    TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1) without sufficient bounds checking. When lighttpd s request…

  • CVE-2025-63154HigNov 10, 2025
    risk 0.49cvss 7.5epss 0.00

    TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2025-63153HigNov 10, 2025
    risk 0.49cvss 7.5epss 0.00

    TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63459HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63465HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63464HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63463HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63462HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63461HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63460HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63469HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63468HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63467HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-63466HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-60336HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.02

    A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2025-60335HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.02

    A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2025-60334HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-60333HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-52905HigSep 23, 2025
    risk 0.49cvss 7.5epss 0.08

    Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

  • CVE-2025-55588HigAug 18, 2025
    risk 0.49cvss 7.5epss 0.00

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-55587HigAug 18, 2025
    risk 0.49cvss 7.5epss 0.00

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-55586HigAug 18, 2025
    risk 0.49cvss 7.5epss 0.00

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-28135HigMar 27, 2025
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi.

  • CVE-2024-46424HigSep 16, 2024
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.

  • CVE-2024-36650HigJun 11, 2024
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/lib/cste_modules/system.so`, the length of the user input string `NoticeUrl` is not checked. This can lead to a buffer overflow, allowing…

  • CVE-2024-33820HigMay 1, 2024
    risk 0.49cvss 7.5epss 0.01

    Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow.

  • CVE-2024-31816HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.03

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.

  • CVE-2024-25468HigFeb 17, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.

  • CVE-2023-46992HigOct 31, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.

  • CVE-2023-46978HigOct 31, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication.

  • CVE-2023-45985HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-34669HigJul 17, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

  • CVE-2023-24147HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini.

  • CVE-2022-48069HigJan 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Totolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter.

  • CVE-2022-40112HigSep 6, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in binary /bin/boa.

  • CVE-2022-40110HigSep 6, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa.

  • CVE-2022-37841HigSep 6, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.

  • CVE-2022-32053HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.

Page 18 of 26