VYPR

Vendor CVEs

Totolink

All CVEs

1,253 total · sorted by risk
  • CVE-2025-44839MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the magicid parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-3987MedApr 27, 2025
    risk 0.42cvss 6.3epss 0.10

    A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The…

  • CVE-2025-28017MedApr 23, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.

  • CVE-2025-28031MedApr 22, 2025
    risk 0.42cvss 6.5epss 0.00

    TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.

  • CVE-2025-28136MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.

  • CVE-2025-2094MedMar 7, 2025
    risk 0.42cvss 6.3epss 0.13

    A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliKey/key leads to os command injection. The…

  • CVE-2025-1829MedMar 2, 2025
    risk 0.42cvss 6.3epss 0.12

    A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknatCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mtkhnatEnable leads to os command injection. The attack can…

  • CVE-2025-25605MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.

  • CVE-2025-25604MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.

  • CVE-2024-53333MedNov 21, 2024
    risk 0.42cvss 6.3epss 0.19

    TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.

  • CVE-2024-34206MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.

  • CVE-2024-34202MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.

  • CVE-2024-32334MedApr 18, 2024
    risk 0.42cvss 6.5epss 0.00

    TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.

  • CVE-2024-31812MedApr 8, 2024
    risk 0.42cvss 6.5epss 0.00

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.

  • CVE-2024-31806MedApr 8, 2024
    risk 0.42cvss 6.5epss 0.00

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.

  • CVE-2024-31805MedApr 8, 2024
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.

  • CVE-2024-1781MedFeb 23, 2024
    risk 0.42cvss 6.3epss 0.15

    A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been…

  • CVE-2021-43662MedMar 31, 2022
    risk 0.42cvss 6.5epss 0.01

    totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.

  • CVE-2021-34228MedAug 20, 2021
    risk 0.42cvss 6.1epss 0.29

    Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.

  • CVE-2018-13313MedFeb 24, 2020
    risk 0.42cvss 6.5epss 0.01

    In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user knows their current password before allowing them to change their password.…

  • CVE-2026-9513MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.01

    A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument host_time can lead to os command injection. The attack can…

  • CVE-2026-9512MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.01

    A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command…

  • CVE-2026-9511MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the…

  • CVE-2026-7721MedMay 4, 2026
    risk 0.41cvss 6.3epss 0.01

    A security vulnerability has been detected in Totolink WA300 5.2cu.7112_B20190227. This affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument hostTime leads to command injection. The attack can be executed remotely. The exploit…

  • CVE-2026-7720MedMay 4, 2026
    risk 0.41cvss 6.3epss 0.01

    A weakness has been identified in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument langType causes command injection. Remote…

  • CVE-2026-7718MedMay 4, 2026
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was identified in Totolink WA300 5.2cu.7112_B20190227. Impacted is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument webWlanIdx leads to command injection. The attack may be…

  • CVE-2026-5178MedMar 31, 2026
    risk 0.41cvss 6.3epss 0.04

    A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument vlanPriLan3 leads to command injection. Remote exploitation of the attack is…

  • CVE-2026-5177MedMar 31, 2026
    risk 0.41cvss 6.3epss 0.02

    A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched…

  • CVE-2026-5105MedMar 30, 2026
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument pptpPassThru results in command injection. It…

  • CVE-2026-5104MedMar 30, 2026
    risk 0.41cvss 6.3epss 0.02

    A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Impacted is the function setStaticRoute of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ip leads to command injection. The attack may be performed from remote. The exploit…

  • CVE-2026-5103MedMar 30, 2026
    risk 0.41cvss 6.3epss 0.04

    A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection. The attack is possible to be carried out remotely. The…

  • CVE-2026-5102MedMar 30, 2026
    risk 0.41cvss 6.3epss 0.02

    A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument qos_up_bw results in command injection. The…

  • CVE-2026-5101MedMar 29, 2026
    risk 0.41cvss 6.3epss 0.02

    A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument lanIp leads to command injection. Remote exploitation of the attack…

  • CVE-2026-5030MedMar 29, 2026
    risk 0.41cvss 6.3epss 0.02

    A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection. The attack can be…

  • CVE-2026-5020MedMar 29, 2026
    risk 0.41cvss 6.3epss 0.02

    A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack…

  • CVE-2026-2167MedFeb 8, 2026
    risk 0.41cvss 6.3epss 0.02

    A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Ipaddr results in os command injection. The attack may be performed from remote. The exploit…

  • CVE-2026-1623MedJan 29, 2026
    risk 0.41cvss 6.3epss 0.02

    A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to…

  • CVE-2026-1601MedJan 29, 2026
    risk 0.41cvss 6.3epss 0.02

    A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument FileName can lead to command injection. The attack can be launched remotely. The…

  • CVE-2026-1548MedJan 28, 2026
    risk 0.41cvss 6.3epss 0.03

    A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument url causes command injection. The attack can be initiated remotely. The exploit has been published and…

  • CVE-2026-1547MedJan 28, 2026
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now…

  • CVE-2026-1327MedJan 22, 2026
    risk 0.41cvss 6.3epss 0.03

    A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Such manipulation of the argument command leads to command injection.…

  • CVE-2026-1326MedJan 22, 2026
    risk 0.41cvss 6.3epss 0.03

    A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument Hostname causes command injection. The attack can…

  • CVE-2026-1150MedJan 19, 2026
    risk 0.41cvss 6.3epss 0.02

    A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack can be…

  • CVE-2026-1149MedJan 19, 2026
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument ip leads to command injection. The attack can be…

  • CVE-2026-0641MedJan 6, 2026
    risk 0.41cvss 6.3epss 0.02

    A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_FILENAME leads to command injection. The attack may be initiated remotely. The…

  • CVE-2025-14586MedDec 13, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the…

  • CVE-2025-9934MedSep 4, 2025
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has…

  • CVE-2025-8938MedAug 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boafrm/formSysTel of the component Telnet Service. The manipulation of the argument TelEnabled leads to backdoor. The attack may be initiated remotely. The…

  • CVE-2025-8937MedAug 14, 2025
    risk 0.41cvss 6.3epss 0.02

    A vulnerability has been found in TOTOLINK N350R 1.2.3-B20130826. This vulnerability affects unknown code of the file /boafrm/formSysCmd. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…

  • CVE-2025-7615MedJul 14, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the function clearPairCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip leads to command injection.…

Page 22 of 26