← Back

Totolink

totolink

1,106 CVEs • 155 products

Products (155)

Click to collapse
Toggle
T6 Firmware
t6_firmware
T8 Firmware
t8_firmware
X15 Firmware
x15_firmware
T10 Firmware
t10_firmware
X18 Firmware
x18_firmware
Wa1200 Poe
wa1200-poe
Soho
soho
A3002ru
a3002ru
A702r
a702r
N301rt
n301rt
N302r
n302r
N300rt
n300rt
N200re
n200re
N150rt
n150rt
N100re
n100re
A850r V1
a850r-v1
F1 V2
f1-v2
F2 V1
f2-v1
N150rt V2
n150rt-v2
N151rt V2
n151rt-v2
N300rh V2
n300rh-v2
N300rh V3
n300rh-v3
N300rt V2
n300rt-v2
A3002r
a3002r
A3002ru V1
a3002ru-v1
A3002ru V2
a3002ru-v2
A702r V2
a702r-v2
A702r V3
a702r-v3

CVEs (1,106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1A3002r Firmware
Jun 17, 2025
May 1, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the w...Show more
Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow.Show less
1Totolink
1N300rt Firmware
Apr 3, 2025
Apr 18, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.
1Totolink
1N300rt Firmware
Apr 3, 2025
Apr 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
1Totolink
1N300rt Firmware
Apr 3, 2025
Apr 18, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.
1Totolink
1N300rt Firmware
Apr 3, 2025
Apr 18, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page.
1Totolink
1N300rt Firmware
Apr 3, 2025
Apr 18, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.
1Totolink
1Ex200 Firmware
Apr 7, 2025
Apr 18, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.
1Totolink
1Ex200 Firmware
May 13, 2025
Apr 18, 2024
N/A· v4
2.4 LOW· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.
1Totolink
1X2000r Firmware
Apr 8, 2025
Apr 11, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
1Totolink
1Ex200 Firmware
Mar 24, 2025
Apr 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
1Totolink
1Ex200 Firmware
Mar 18, 2025
Apr 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.
1Totolink
1Ex200 Firmware
Jun 17, 2025
Apr 8, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
1Totolink
1Ex200 Firmware
Mar 18, 2025
Apr 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.
1Totolink
1Ex200 Firmware
Mar 18, 2025
Apr 8, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.
1Totolink
1Ex200 Firmware
Mar 18, 2025
Apr 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.
1Totolink
1Ex200 Firmware
Mar 18, 2025
Apr 8, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.
1Totolink
1Ex200 Firmware
Mar 18, 2025
Apr 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.
1Totolink
1Ex200 Firmware
Mar 18, 2025
Apr 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
1Totolink
1Ex200 Firmware
Mar 18, 2025
Apr 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.
1Totolink
1Ex200 Firmware
Mar 18, 2025
Apr 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.