VYPR

Vendor CVEs

Totolink

All CVEs

1,425 total · sorted by risk
  • CVE-2024-0579MedJan 16, 2024
    risk 0.41cvss 6.3epss 0.02

    A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads to command injection. The attack can be…

  • CVE-2024-0293MedJan 8, 2024
    risk 0.41cvss 6.3epss 0.05

    A vulnerability classified as critical was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this vulnerability is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack can…

  • CVE-2024-0292MedJan 8, 2024
    risk 0.41cvss 6.3epss 0.05

    A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to os command injection. It is possible to launch the attack…

  • CVE-2024-0291MedJan 8, 2024
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack may be…

  • CVE-2023-7214MedJan 7, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument v8…

  • CVE-2023-7213MedJan 7, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this vulnerability is the function main of the file /cgi-bin/cstecgi.cgi?action=login&flag=1 of the component HTTP POST Request Handler. The manipulation of the argument v33…

  • CVE-2023-4412MedAug 18, 2023
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This issue affects the function setWanCfg. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…

  • CVE-2023-4411MedAug 18, 2023
    risk 0.41cvss 6.3epss 0.05

    A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2023-4410MedAug 18, 2023
    risk 0.41cvss 6.3epss 0.04

    A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed…

  • CVE-2024-32332MedApr 18, 2024
    risk 0.40cvss 6.1epss 0.00

    TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page.

  • CVE-2020-23617MedMay 2, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.

  • CVE-2021-43661MedMar 31, 2022
    risk 0.40cvss 6.1epss 0.01

    totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.

  • CVE-2021-34223MedAug 20, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.

  • CVE-2021-34220MedAug 20, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.

  • CVE-2021-34215MedAug 20, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.

  • CVE-2021-34207MedAug 20, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field.

  • CVE-2018-13317MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.

  • CVE-2018-13312MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.

  • CVE-2018-13310MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.

  • CVE-2018-13309MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.

  • CVE-2018-13308MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.

  • CVE-2024-32354MedMay 14, 2024
    risk 0.39cvss 6.0epss 0.01

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

  • CVE-2024-32349MedMay 14, 2024
    risk 0.39cvss 6.0epss 0.01

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.

  • CVE-2026-51756MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51748MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51742MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51739MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51714MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51712MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless availability windows via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2024-35401MedMay 28, 2024
    risk 0.38cvss 5.9epss 0.01

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

  • CVE-2024-28402MedApr 11, 2024
    risk 0.38cvss 5.9epss 0.00

    TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.

  • CVE-2023-6612MedDec 8, 2023
    risk 0.38cvss 5.5epss 0.31

    A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDynamicRoute/setFirewallType/setIPSecCfg/setIpPortFilterRules/setLancfg/setLoginPasswordCfg/setMacFilterRules/setMtknatCfg/setNetworkC…

  • CVE-2026-5679MedApr 6, 2026
    risk 0.36cvss 5.5epss 0.02

    A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command injection. The exploit has been disclosed…

  • CVE-2024-7159MedJul 28, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been rated as critical. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. The…

  • CVE-2024-7156MedJul 28, 2024
    risk 0.36cvss 5.3epss 0.13

    A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/ExportSettings.sh of the component apmib Configuration Handler. The manipulation leads to information…

  • CVE-2024-32327MedApr 18, 2024
    risk 0.36cvss 5.5epss 0.00

    TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.

  • CVE-2023-7187MedDec 31, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in Totolink N350RT 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi?action=login&flag=ie8 of the component HTTP POST Request Handler. The manipulation leads to stack-based…

  • CVE-2022-48067MedJan 27, 2023
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to obtain the root password via a brute-force attack.

  • CVE-2020-27368MedJan 14, 2021
    risk 0.36cvss 5.5epss 0.00

    Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.

  • CVE-2026-51703MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter when Wi-Fi is available via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2025-45867MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.05

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.

  • CVE-2025-45866MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.00

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.

  • CVE-2025-45864MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.05

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.

  • CVE-2025-45859MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.05

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.

  • CVE-2025-4270MedMay 5, 2025
    risk 0.35cvss 5.3epss 0.13

    A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl with the input getInitCfg/getSysStatusCfg…

  • CVE-2025-4268MedMay 5, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input RebootSystem leads to missing authentication. The attack…

  • CVE-2025-3668MedApr 16, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be initiated…

  • CVE-2025-3663MedApr 16, 2025
    risk 0.35cvss 5.3epss 0.11

    A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component Password Handler. The manipulation leads to improper…

  • CVE-2024-10654MedNov 1, 2024
    risk 0.35cvss 5.3epss 0.02

    A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The…

  • CVE-2024-32335MedApr 18, 2024
    risk 0.35cvss 5.4epss 0.00

    TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.

Page 26 of 29