← Back

Totolink

totolink

1,106 CVEs • 155 products

Products (155)

Click to collapse
Toggle
T6 Firmware
t6_firmware
T8 Firmware
t8_firmware
X15 Firmware
x15_firmware
T10 Firmware
t10_firmware
X18 Firmware
x18_firmware
Wa1200 Poe
wa1200-poe
Soho
soho
A3002ru
a3002ru
A702r
a702r
N301rt
n301rt
N302r
n302r
N300rt
n300rt
N200re
n200re
N150rt
n150rt
N100re
n100re
A850r V1
a850r-v1
F1 V2
f1-v2
F2 V1
f2-v1
N150rt V2
n150rt-v2
N151rt V2
n151rt-v2
N300rh V2
n300rh-v2
N300rh V3
n300rh-v3
N300rt V2
n300rt-v2
A3002r
a3002r
A3002ru V1
a3002ru-v1
A3002ru V2
a3002ru-v2
A702r V2
a702r-v2
A702r V3
a702r-v3

CVEs (1,106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in /setting/setDiagnosisCfg.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.
1Totolink
1N600r Firmware
Nov 21, 2024
May 10, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parameter in /setting/setDeviceName.
1Totolink
1N600r Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Main" function.
1Totolink
1A7100ru Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully co...Show more
It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a careful...Show more
It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully co...Show more
It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefull...Show more
It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payloadShow less
1Totolink
2N100re Firmware
N200re Firmware
Nov 21, 2024
May 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
1Totolink
1Ex300 V2 Firmware
Nov 21, 2024
Mar 31, 2022
N/A· v4
7.5 HIGH· v3
7.9 HIGH· v2
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.
1Totolink
2A720r Firmware
Ex300 V2 Firmware
Nov 21, 2024
Mar 31, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.
1Totolink
1Ex300 V2 Firmware
Nov 21, 2024
Mar 31, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.
1Totolink
2Ex1200t Firmware
Ex300 V2 Firmware
Nov 21, 2024
Mar 30, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
1Totolink
1A3100r Firmware
Nov 21, 2024
Mar 30, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.