← Back

Totolink

totolink

1,106 CVEs • 155 products

Products (155)

Click to collapse
Toggle
T6 Firmware
t6_firmware
T8 Firmware
t8_firmware
X15 Firmware
x15_firmware
T10 Firmware
t10_firmware
X18 Firmware
x18_firmware
Wa1200 Poe
wa1200-poe
Soho
soho
A3002ru
a3002ru
A702r
a702r
N301rt
n301rt
N302r
n302r
N300rt
n300rt
N200re
n200re
N150rt
n150rt
N100re
n100re
A850r V1
a850r-v1
F1 V2
f1-v2
F2 V1
f2-v1
N150rt V2
n150rt-v2
N151rt V2
n151rt-v2
N300rh V2
n300rh-v2
N300rh V3
n300rh-v3
N300rt V2
n300rt-v2
A3002r
a3002r
A3002ru V1
a3002ru-v1
A3002ru V2
a3002ru-v2
A702r V2
a702r-v2
A702r V3
a702r-v3

CVEs (1,106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
6A3000ru Firmware
A3100r FirmwareA800r Firmware+3 more
Nov 21, 2024
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to conta...Show more
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setDiagnosisCfg, via the ipDoamin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Totolink
6A3000ru Firmware
A3100r FirmwareA800r Firmware+3 more
Nov 21, 2024
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to conta...Show more
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setLanguageCfg, via the langType parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Totolink
1A3100r Firmware
Nov 21, 2024
Mar 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
1Totolink
1T6 Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
1Totolink
1A860r Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
1Totolink
1A950rg Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via...Show more
TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.Show less
1Totolink
1T10 V2 Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
1Totolink
1A830r Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
1Totolink
1A810r Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
1Totolink
1A3600r Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter...Show more
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.Show less
1Totolink
1A3100r Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter...Show more
TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.Show less
1Totolink
1A800r Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
1Totolink
1A3000ru Firmware
Nov 21, 2024
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
1Totolink
2T10 Firmware
T6 Firmware
Nov 21, 2024
Feb 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbi...Show more
A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.Show less
1Totolink
2T10 Firmware
T6 Firmware
Nov 21, 2024
Feb 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitra...Show more
A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.Show less
1Totolink
1T6 Firmware
Nov 21, 2024
Feb 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
1T6 Firmware
Nov 21, 2024
Feb 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
1T6 Firmware
Nov 21, 2024
Feb 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
2T10 Firmware
T6 Firmware
Nov 21, 2024
Feb 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
2T10 Firmware
T6 Firmware
Nov 21, 2024
Feb 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execu...Show more
A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.Show less