VYPR

Vendor CVEs

Totolink

All CVEs

1,425 total · sorted by risk
  • CVE-2025-28256CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.

  • CVE-2025-28138CriMar 27, 2025
    risk 0.64cvss 9.8epss 0.01

    The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

  • CVE-2024-52723CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.

  • CVE-2024-46419CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.

  • CVE-2024-46451CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.

  • CVE-2024-34195CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversight leads to potential buffer overflow…

  • CVE-2024-34198CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying…

  • CVE-2024-8162CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.02

    A vulnerability classified as critical has been found in TOTOLINK T10 AC1200 4.1.8cu.5207. Affected is an unknown function of the file /squashfs-root/web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to hard-coded credentials. It is possible to…

  • CVE-2024-42967CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.

  • CVE-2024-42966CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.

  • CVE-2024-42547CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.

  • CVE-2024-42546CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.

  • CVE-2024-42545CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.

  • CVE-2024-42543CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.

  • CVE-2024-42520CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.

  • CVE-2024-41319CriJul 23, 2024
    risk 0.64cvss 9.8epss 0.06

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

  • CVE-2024-41318CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

  • CVE-2024-41316CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

  • CVE-2024-37637CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.

  • CVE-2024-37635CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg

  • CVE-2024-37634CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.

  • CVE-2024-37632CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .

  • CVE-2024-36782CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.00

    TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

  • CVE-2024-36783CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.

  • CVE-2024-35398CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules.

  • CVE-2024-35387CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.06

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

  • CVE-2024-35396CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.

  • CVE-2024-32353CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

  • CVE-2024-35099CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

  • CVE-2024-34213CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.

  • CVE-2024-34209CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.

  • CVE-2024-34204CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.

  • CVE-2024-31810CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2024-34257CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.

  • CVE-2024-31807CriApr 8, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.

  • CVE-2024-28639CriMar 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.

  • CVE-2024-1783CriFeb 23, 2024
    risk 0.64cvss 9.8epss 0.02

    A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi of the component Web Interface. The manipulation of the argument http_host leads to…

  • CVE-2024-24333CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.

  • CVE-2024-24332CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.

  • CVE-2024-24331CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.

  • CVE-2024-24330CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.

  • CVE-2024-24329CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.06

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.

  • CVE-2024-24328CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.06

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.

  • CVE-2024-24327CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.

  • CVE-2024-24326CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.

  • CVE-2024-24325CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.

  • CVE-2024-24324CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

  • CVE-2024-22529CriJan 25, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.

  • CVE-2023-52040CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.

  • CVE-2023-52039CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.

Page 5 of 29