← Back

Totolink

totolink

1,106 CVEs • 155 products

Products (155)

Click to collapse
Toggle
T6 Firmware
t6_firmware
T8 Firmware
t8_firmware
X15 Firmware
x15_firmware
T10 Firmware
t10_firmware
X18 Firmware
x18_firmware
Wa1200 Poe
wa1200-poe
Soho
soho
A3002ru
a3002ru
A702r
a702r
N301rt
n301rt
N302r
n302r
N300rt
n300rt
N200re
n200re
N150rt
n150rt
N100re
n100re
A850r V1
a850r-v1
F1 V2
f1-v2
F2 V1
f2-v1
N150rt V2
n150rt-v2
N151rt V2
n151rt-v2
N300rh V2
n300rh-v2
N300rh V3
n300rh-v3
N300rt V2
n300rt-v2
A3002r
a3002r
A3002ru V1
a3002ru-v1
A3002ru V2
a3002ru-v2
A702r V2
a702r-v2
A702r V3
a702r-v3

CVEs (1,106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1T6 Firmware
Nov 21, 2024
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.
1Totolink
1T6 Firmware
Nov 21, 2024
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.
1Totolink
1T6 Firmware
Nov 21, 2024
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can control deviceName to attack.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control thedeviceName to attack.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 2, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
1Totolink
1Ex1200t Firmware
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.
1Totolink
1A3600r Firmware
Nov 21, 2024
May 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT...Show more
Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.Show less
1Totolink
1A3100r Firmware
Nov 21, 2024
May 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtain sensitive information via a crafted web request.
1Totolink
1A3100r Firmware
Nov 21, 2024
May 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component /etc/shadow.sample.
1Totolink
1A3100r Firmware
Nov 21, 2024
May 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in the component /web_cste/cgi-bin/product.ini.