← Back

Totolink

totolink

1,106 CVEs • 155 products

Products (155)

Click to collapse
Toggle
T6 Firmware
t6_firmware
T8 Firmware
t8_firmware
X15 Firmware
x15_firmware
T10 Firmware
t10_firmware
X18 Firmware
x18_firmware
Wa1200 Poe
wa1200-poe
Soho
soho
A3002ru
a3002ru
A702r
a702r
N301rt
n301rt
N302r
n302r
N300rt
n300rt
N200re
n200re
N150rt
n150rt
N100re
n100re
A850r V1
a850r-v1
F1 V2
f1-v2
F2 V1
f2-v1
N150rt V2
n150rt-v2
N151rt V2
n151rt-v2
N300rh V2
n300rh-v2
N300rh V3
n300rh-v3
N300rt V2
n300rt-v2
A3002r
a3002r
A3002ru V1
a3002ru-v1
A3002ru V2
a3002ru-v2
A702r V2
a702r-v2
A702r V3
a702r-v3

CVEs (1,106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1X5000r Firmware
Nov 21, 2024
Aug 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
1Totolink
1Ex1200l Firmware
Nov 21, 2024
Aug 18, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This issue affects the function setWanCfg. The manipulation leads to os command injection. The attack may be initiated r...Show more
A vulnerability was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This issue affects the function setWanCfg. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237515. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Totolink
1Ex1200l Firmware
Nov 21, 2024
Aug 18, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attac...Show more
A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-237514 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Totolink
1Ex1200l Firmware
Nov 21, 2024
Aug 18, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to ini...Show more
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237513 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Totolink
1T10 V2 Firmware
Nov 21, 2024
Aug 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the retur...Show more
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code.Show less
1Totolink
1T10 V2 Firmware
Nov 21, 2024
Aug 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return addre...Show more
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code.Show less
1Totolink
1Cp300+ Firmware
Nov 21, 2024
Jul 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.
1Totolink
1A3300r Firmware
Nov 21, 2024
Jul 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.
1Totolink
1A3300r Firmware
Nov 21, 2024
Jul 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
1Totolink
1A3300r Firmware
Nov 21, 2024
Jul 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.
1Totolink
1A3300r Firmware
Nov 21, 2024
Jul 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
1Totolink
1Lr350 Firmware
Nov 21, 2024
Jul 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
1Totolink
1Lr350 Firmware
Nov 21, 2024
Jul 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
1Totolink
1Lr350 Firmware
Nov 21, 2024
Jul 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
1Totolink
1Lr350 Firmware
Nov 21, 2024
Jul 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
1Totolink
1A7100ru Firmware
Jan 7, 2025
Jun 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.
1Totolink
1X5000r Firmware
Jan 8, 2025
Jun 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
1Totolink
1X5000r Firmware
Jan 9, 2025
May 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" paramet...Show more
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.Show less
1Totolink
1X5000r Firmware
Jan 9, 2025
May 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" para...Show more
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.Show less
1Totolink
1X5000r Firmware
Jan 10, 2025
May 31, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.