totolink
1,196 tracked vulnerabilities.
CVE-2025-51452
CRITICAL
TOTOLINK A7000R <9.1.0u.6115_B20201022 - Auth Bypass
Aug 13, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-51390
CRITICAL
TOTOLINK N600R V4.3.0cu.7647_B20210106 - Command Injection
Aug 04, 2025
CVSS 9.8
EPSS 0.02
CVE-2025-52284
MEDIUM
Totolink X6000R V9.4.0cu.1360_B20241207 - Unauthenticated Command Injection via tz Parameter
Jul 29, 2025
CVSS 6.5
EPSS 0.27
CVE-2025-8246
HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via HTTP POST Request Handler
Jul 27, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8245
HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via formMultiAPVLAN submit-url Parameter
Jul 27, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8244
HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via formMapDelDevice macstr Parameter
Jul 27, 2025
CVSS 8.8
EPSS 0.02
CVE-2025-8243
HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via devicemac1 Parameter
Jul 27, 2025
CVSS 8.8
EPSS 0.02
CVE-2025-8242
HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via HTTP POST Request Handler
Jul 27, 2025
CVSS 8.8
EPSS 0.03
CVE-2025-8181
HIGH
TOTOLINK N600R/X2000R 1.0.0.1 - Privilege Escalation
Jul 26, 2025
CVSS 7.2
EPSS 0.01
CVE-2025-8170
HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow in MQTT Packet Handler via tcpcheck_net serverIp Argument
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8140
HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formWlanMultipleAP HTTP POST Request Handler
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8139
HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formPortFw service_type Parameter
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8138
HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formOneKeyAccessButton submit-url Parameter
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8137
HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via HTTP POST Request Handler
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8136
HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formFilter ip6addr Parameter
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7952
MEDIUM
TOTOLINK T6 4.1.5cu.748 - Command Injection
Jul 22, 2025
CVSS 6.3
EPSS 0.08
CVE-2025-44655
CRITICAL
TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9 - Privilege Escalation via vsftpd chroot_local_user Misconfiguration
Jul 21, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-7913
HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 21, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7912
HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 20, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7862
HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Missing Authentication
Jul 20, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-7837
HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 19, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7758
HIGH
TOTOLINK T6 <4.1.5cu.748_B20211015 - Buffer Overflow
Jul 17, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-52046
CRITICAL
Totolink A3300R V17.0.0cu.596_B20250515 - Unauthenticated Command Injection via mac and desc Parameters
Jul 17, 2025
CVSS 9.8
EPSS 0.62
CVE-2025-51630
CRITICAL
TOTOLINK N350RT V9.3.5u.6139_B20201216 - Buffer Overflow via ePort Parameter in setIpPortFilterRules
Jul 17, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-7615
MEDIUM
TOTOLINK T6 4.1.5cu.748 - Command Injection
Jul 14, 2025
CVSS 6.3
EPSS 0.05
Products
x5000r_firmware 70
a3002r_firmware 61
x6000r_firmware 57
a3300r_firmware 55
a3002ru_firmware 49
a3100r_firmware 47
x2000r_firmware 45
a3700r_firmware 43
A7100RU 40
t6_firmware 39
n600r_firmware 38
a7100ru_firmware 37
ex1200t_firmware 37
A8000RU 36
lr350_firmware 36
a7000r_firmware 35
a950rg_firmware 33
a702r_firmware 32
a810r_firmware 29
a720r_firmware 28
ex1800t_firmware 28
nr1800x_firmware 27
t8_firmware 26
a3000ru_firmware 25
a3600r_firmware 25
a830r_firmware 25
x15_firmware 25
ca300-poe_firmware 24
a800r_firmware 23
t10_firmware 22
Quick Filters