← Back

Totolink

totolink

1,106 CVEs • 155 products

Products (155)

Click to collapse
Toggle
T6 Firmware
t6_firmware
T8 Firmware
t8_firmware
X15 Firmware
x15_firmware
T10 Firmware
t10_firmware
X18 Firmware
x18_firmware
Wa1200 Poe
wa1200-poe
Soho
soho
A3002ru
a3002ru
A702r
a702r
N301rt
n301rt
N302r
n302r
N300rt
n300rt
N200re
n200re
N150rt
n150rt
N100re
n100re
A850r V1
a850r-v1
F1 V2
f1-v2
F2 V1
f2-v1
N150rt V2
n150rt-v2
N151rt V2
n151rt-v2
N300rh V2
n300rh-v2
N300rh V3
n300rh-v3
N300rt V2
n300rt-v2
A3002r
a3002r
A3002ru V1
a3002ru-v1
A3002ru V2
a3002ru-v2
A702r V2
a702r-v2
A702r V3
a702r-v3

CVEs (1,106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1A7100ru Firmware
Apr 3, 2025
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the setting/setOpenVpnCertGenerationCfg function.
1Totolink
1A7100ru Firmware
Apr 3, 2025
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setting/delStaticDhcpRules function.
1Totolink
1A7100ru Firmware
Apr 3, 2025
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the setting/delStaticDhcpRules function.
1Totolink
1A7100ru Firmware
Apr 3, 2025
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the setting/delStaticDhcpRules function.
1Totolink
1A7100ru Firmware
Apr 4, 2025
Jan 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root shell through a specially constructed payload.
1Totolink
1A7100ru Firmware
Apr 21, 2025
Dec 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.
1Totolink
1A7100ru Firmware
Apr 21, 2025
Dec 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.
1Totolink
1A7100ru Firmware
Apr 29, 2025
Nov 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.
1Totolink
1A7100ru Firmware
Apr 29, 2025
Nov 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.
1Totolink
1Nr1800x Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
1Totolink
1Lr350 Firmware
Apr 25, 2025
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.