← Back

Cp900l Firmware

cp900l_firmware

Vendor: Totolink • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1Cp900l Firmware
Jun 17, 2026
May 28, 2024
N/A· v4
2.7 LOW· v3
N/A· v2
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRules
1Totolink
1Cp900l Firmware
Jul 9, 2026
May 28, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
1Totolink
1Cp900l Firmware
Jul 9, 2026
May 28, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules
1Totolink
1Cp900l Firmware
Jul 9, 2026
May 28, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth
1Totolink
1Cp900l Firmware
Jul 9, 2026
May 28, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules.
1Totolink
1Cp900l Firmware
Jul 9, 2026
May 28, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary com...Show more
TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Totolink
1Cp900l Firmware
Jul 9, 2026
May 24, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.
1Totolink
1Cp900l Firmware
Jul 9, 2026
May 24, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.