VYPR

Vendor CVEs

Totolink

All CVEs

1,425 total · sorted by risk
  • CVE-2024-29419MedMar 20, 2024
    risk 0.35cvss 5.4epss 0.00

    There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.

  • CVE-2024-28401MedMar 15, 2024
    risk 0.35cvss 5.4epss 0.00

    TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.

  • CVE-2024-28403MedMar 15, 2024
    risk 0.35cvss 5.4epss 0.00

    TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.

  • CVE-2023-7223MedJan 9, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to improper access controls. It is possible to…

  • CVE-2022-29646MedMay 18, 2022
    risk 0.35cvss 5.3epss 0.01

    An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtain sensitive information via a crafted web request.

  • CVE-2021-34218MedAug 20, 2021
    risk 0.35cvss 5.3epss 0.01

    Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.

  • CVE-2026-51761MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51752MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51745MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51737MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51732MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51727MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-11620MedJun 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results in least privilege violation. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-0731MedJan 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been found in TOTOLINK WA1200 5.9c.2914. The impacted element is an unknown function of the file cstecgi.cgi of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack is possible to be carried out remotely. The…

  • CVE-2025-57623MedSep 25, 2025
    risk 0.34cvss 5.3epss 0.00

    A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.

  • CVE-2025-55584MedAug 18, 2025
    risk 0.34cvss 5.3epss 0.00

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.

  • CVE-2025-4271MedMay 5, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to information…

  • CVE-2025-3675MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack may be launched remotely.…

  • CVE-2025-3674MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched…

  • CVE-2025-3667MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The…

  • CVE-2025-3666MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit…

  • CVE-2025-3665MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched…

  • CVE-2025-3664MedApr 16, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to launch the attack remotely.…

  • CVE-2025-2955MedMar 30, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/ExportIbmsConfig.sh of the component IBMS Configuration File Handler. The manipulation leads to improper access…

  • CVE-2024-35400MedMay 28, 2024
    risk 0.34cvss 5.3epss 0.00

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules

  • CVE-2025-60686MedNov 13, 2025
    risk 0.33cvss 5.1epss 0.00

    A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using…

  • CVE-2025-60685MedNov 13, 2025
    risk 0.33cvss 5.1epss 0.00

    A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file using fgets() into a local buffer and subsequently parses the line using sscanf() into a single-byte…

  • CVE-2025-25524MedFeb 11, 2025
    risk 0.33cvss 5.1epss 0.00

    Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or…

  • CVE-2024-57212MedJan 10, 2025
    risk 0.33cvss 5.1epss 0.01

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.

  • CVE-2024-8869MedSep 15, 2024
    risk 0.33cvss 5.0epss 0.02

    A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is…

  • CVE-2025-6299MedJun 20, 2025
    risk 0.31cvss 4.7epss 0.12

    A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the argument targetAPSsid leads to os command injection. It is possible to initiate the attack remotely. The…

  • CVE-2024-33433MedMay 14, 2024
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.

  • CVE-2025-22903MedApr 15, 2025
    risk 0.30cvss 4.6epss 0.00

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.

  • CVE-2026-51706MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51704MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51702MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51683MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51678MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51667MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51666MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device initialization state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51665MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain traceroute diagnostic logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51664MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51656MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain VPN pass-through and WAN ping filter settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51655MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51654MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51653MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51652MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain UPnP enablement and parsed port-mapping information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51651MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Smart QoS configuration and rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51640MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getMeshNeighborTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh neighbor information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51639MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain AP-specific Wi-Fi scheduling rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.