← Back

Totolink

totolink

1,106 CVEs • 155 products

Products (155)

Click to collapse
Toggle
T6 Firmware
t6_firmware
T8 Firmware
t8_firmware
X15 Firmware
x15_firmware
T10 Firmware
t10_firmware
X18 Firmware
x18_firmware
Wa1200 Poe
wa1200-poe
Soho
soho
A3002ru
a3002ru
A702r
a702r
N301rt
n301rt
N302r
n302r
N300rt
n300rt
N200re
n200re
N150rt
n150rt
N100re
n100re
A850r V1
a850r-v1
F1 V2
f1-v2
F2 V1
f2-v1
N150rt V2
n150rt-v2
N151rt V2
n151rt-v2
N300rh V2
n300rh-v2
N300rh V3
n300rh-v3
N300rt V2
n300rt-v2
A3002r
a3002r
A3002ru V1
a3002ru-v1
A3002ru V2
a3002ru-v2
A702r V2
a702r-v2
A702r V3
a702r-v3

CVEs (1,106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1A3002ru Firmware
Nov 21, 2024
Dec 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.
1Totolink
1X6000r Firmware
Nov 21, 2024
Dec 4, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resultin...Show more
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Dec 4, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.
1Totolink
1X6000r Firmware
Nov 21, 2024
Dec 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resultin...Show more
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Dec 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracerouteCfg component.
1Totolink
1X6000r Firmware
Nov 21, 2024
Dec 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component.
1Totolink
1X6000r Firmware
Nov 21, 2024
Dec 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.
1Totolink
1X6000r Firmware
Nov 21, 2024
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vuln...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vuln...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vuln...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vuln...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vuln...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vuln...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Nov 21, 2024
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vuln...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1X6000r Firmware
Jun 5, 2025
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vuln...Show more
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.Show less
1Totolink
1A3700r Firmware
Nov 21, 2024
Nov 20, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.
1Totolink
1X6000r Firmware
Nov 21, 2024
Oct 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.
1Totolink
1X6000r Firmware
Nov 21, 2024
Oct 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.