← Back

Totolink

totolink

1,106 CVEs • 155 products

Products (155)

Click to collapse
Toggle
T6 Firmware
t6_firmware
T8 Firmware
t8_firmware
X15 Firmware
x15_firmware
T10 Firmware
t10_firmware
X18 Firmware
x18_firmware
Wa1200 Poe
wa1200-poe
Soho
soho
A3002ru
a3002ru
A702r
a702r
N301rt
n301rt
N302r
n302r
N300rt
n300rt
N200re
n200re
N150rt
n150rt
N100re
n100re
A850r V1
a850r-v1
F1 V2
f1-v2
F2 V1
f2-v1
N150rt V2
n150rt-v2
N151rt V2
n151rt-v2
N300rh V2
n300rh-v2
N300rh V3
n300rh-v3
N300rt V2
n300rt-v2
A3002r
a3002r
A3002ru V1
a3002ru-v1
A3002ru V2
a3002ru-v2
A702r V2
a702r-v2
A702r V3
a702r-v3

CVEs (1,106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1N200re Firmware
Nov 21, 2024
May 18, 2023
N/A· v4
5.5 MEDIUM· v3
1.4 LOW· v2
A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipu...Show more
A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-229374 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Totolink
1A3300r Firmware
Jan 22, 2025
May 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
1Totolink
1Cp300+ Firmware
Jan 23, 2025
May 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
1Totolink
1A7100ru Firmware
Jan 29, 2025
May 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.
1Totolink
1A7100ru Firmware
Jan 29, 2025
May 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
1Totolink
1X5000r Firmware
Jan 29, 2025
May 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "co...Show more
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.Show less
1Totolink
1X18 Firmware
Feb 6, 2025
Apr 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.
1Totolink
1X18 Firmware
Feb 6, 2025
Apr 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
1Totolink
1X18 Firmware
Feb 6, 2025
Apr 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function.
1Totolink
1X18 Firmware
Feb 6, 2025
Apr 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
1Totolink
1X18 Firmware
Nov 21, 2024
Apr 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
1Totolink
1X18 Firmware
Feb 6, 2025
Apr 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.
1Totolink
1A7100ru Firmware
Feb 12, 2025
Apr 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.
1Totolink
1A7100ru Firmware
Feb 12, 2025
Apr 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.
1Totolink
1A7100ru Firmware
Feb 18, 2025
Mar 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg.
1Totolink
1A7100ru Firmware
Feb 18, 2025
Mar 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.
1Totolink
1A7100ru Firmware
Feb 18, 2025
Mar 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg.
1Totolink
1Cp900 Firmware
Feb 20, 2025
Mar 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitra...Show more
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Totolink
1Cp900 Firmware
Nov 21, 2024
Mar 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execu...Show more
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Totolink
1Cp900 Firmware
Nov 21, 2024
Mar 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute ar...Show more
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less