← Back

N600r Firmware

n600r_firmware

Vendor: Totolink • 38 CVEs

CVEs (38)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macAddress parameter in the function FUN_0041b448.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004192cc.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418c24.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004200c8.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUploadSetting.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/CloudACMunualUpdate.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicename parameter in /setting/setDeviceName.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx parameter in /setting/setWebWlanIdx.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in /setting/setDiagnosisCfg.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parameter in /setting/setDeviceName.
1Totolink
1N600r Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Main" function.
1Totolink
1N600r Firmware
Nov 21, 2024
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.
1Totolink
1N600r Firmware
Nov 21, 2024
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.
1Totolink
1N600r Firmware
Nov 21, 2024
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.
1Totolink
1N600r Firmware
Nov 21, 2024
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.