VYPR

Vendor CVEs

Totolink

All CVEs

1,425 total · sorted by risk
  • CVE-2023-48860CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code.

  • CVE-2023-48800CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

  • CVE-2023-48799CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.

  • CVE-2023-48801CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

  • CVE-2023-43455CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracerouteCfg component.

  • CVE-2023-43454CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component.

  • CVE-2023-43453CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.

  • CVE-2023-48812CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48811CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48810CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48808CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48807CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48806CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48805CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48804CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48803CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48802CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-46485CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

  • CVE-2023-46484CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.

  • CVE-2023-46993CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.

  • CVE-2023-46979CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.

  • CVE-2023-46977CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.09

    TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

  • CVE-2023-46976CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.

  • CVE-2023-46424CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function.

  • CVE-2023-46423CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function.

  • CVE-2023-46422CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.

  • CVE-2023-46421CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.

  • CVE-2023-46420CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.

  • CVE-2023-46419CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.

  • CVE-2023-46418CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.

  • CVE-2023-46417CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.

  • CVE-2023-46416CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.

  • CVE-2023-46415CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.

  • CVE-2023-46414CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.

  • CVE-2023-46413CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.

  • CVE-2023-46412CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.

  • CVE-2023-46411CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.

  • CVE-2023-46410CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.

  • CVE-2023-46409CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.

  • CVE-2023-46408CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.

  • CVE-2023-46564CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.

  • CVE-2023-46563CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.

  • CVE-2023-46562CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.

  • CVE-2023-46560CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.

  • CVE-2023-46559CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.

  • CVE-2023-46558CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.

  • CVE-2023-46557CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAPVLAN.

  • CVE-2023-46556CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formFilter.

  • CVE-2023-46555CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPortFw.

  • CVE-2023-46554CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDel.

Page 7 of 29