← Back

Totolink

totolink

1,106 CVEs • 155 products

Products (155)

Click to collapse
Toggle
T6 Firmware
t6_firmware
T8 Firmware
t8_firmware
X15 Firmware
x15_firmware
T10 Firmware
t10_firmware
X18 Firmware
x18_firmware
Wa1200 Poe
wa1200-poe
Soho
soho
A3002ru
a3002ru
A702r
a702r
N301rt
n301rt
N302r
n302r
N300rt
n300rt
N200re
n200re
N150rt
n150rt
N100re
n100re
A850r V1
a850r-v1
F1 V2
f1-v2
F2 V1
f2-v1
N150rt V2
n150rt-v2
N151rt V2
n151rt-v2
N300rh V2
n300rh-v2
N300rh V3
n300rh-v3
N300rt V2
n300rt-v2
A3002r
a3002r
A3002ru V1
a3002ru-v1
A3002ru V2
a3002ru-v2
A702r V2
a702r-v2
A702r V3
a702r-v3

CVEs (1,106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1X5000r Firmware
Mar 17, 2025
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.
1Totolink
1A6000r Firmware
Apr 3, 2025
Jan 10, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
1Totolink
1A6000r Firmware
Apr 3, 2025
Jan 10, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function.
1Totolink
1A6000r Firmware
Apr 3, 2025
Jan 10, 2025
N/A· v4
5.1 MEDIUM· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.
1Totolink
1A6000r Firmware
Apr 3, 2025
Jan 10, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.
1Totolink
1A3002r Firmware
Apr 9, 2025
Dec 26, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
1Totolink
1Ex1800t Firmware
Dec 10, 2024
Dec 9, 2024
5.3 MEDIUM· v4
9.8 CRITICAL· v3
4.0 MEDIUM· v2
A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid l...Show more
A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Totolink
1X6000r Firmware
Mar 13, 2025
Nov 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
1Totolink
1A810r Firmware
Apr 4, 2025
Nov 21, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.
1Totolink
1A810r Firmware
Apr 4, 2025
Nov 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.
1Totolink
1Ex200 Firmware
Apr 4, 2025
Nov 21, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.
1Totolink
1A6000ub Firmware
Jun 17, 2025
Nov 15, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.
1Totolink
1X18 Firmware
Dec 16, 2024
Nov 7, 2024
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the arg...Show more
A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Totolink
1Lr350 Firmware
Mar 10, 2025
Nov 1, 2024
6.9 MEDIUM· v4
9.1 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument a...Show more
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.3.5u.6698_B20230810 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Totolink
1T10 Firmware
Sep 24, 2024
Sep 19, 2024
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument comman...Show more
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Totolink
1T8 Firmware
Sep 17, 2024
Sep 16, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.
1Totolink
1T8 Firmware
Sep 17, 2024
Sep 16, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.
1Totolink
1T8 Firmware
Sep 17, 2024
Sep 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.
1Totolink
1A720r Firmware
Sep 20, 2024
Sep 15, 2024
2.3 LOW· v4
8.1 HIGH· v3
4.6 MEDIUM· v2
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It is possible to launch the attack remotely. The comple...Show more
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Totolink
1T8 Firmware
Sep 10, 2024
Sep 8, 2024
9.2 CRITICAL· v4
8.1 HIGH· v3
7.6 HIGH· v2
A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password....Show more
A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less