totolink

1,196 tracked vulnerabilities.

CVE-2025-51452 CRITICAL
TOTOLINK A7000R <9.1.0u.6115_B20201022 - Auth Bypass
Aug 13, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-51390 CRITICAL
TOTOLINK N600R V4.3.0cu.7647_B20210106 - Command Injection
Aug 04, 2025
CVSS 9.8
EPSS 0.02
CVE-2025-52284 MEDIUM
Totolink X6000R V9.4.0cu.1360_B20241207 - Unauthenticated Command Injection via tz Parameter
Jul 29, 2025
CVSS 6.5
EPSS 0.27
CVE-2025-8246 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via HTTP POST Request Handler
Jul 27, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8245 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via formMultiAPVLAN submit-url Parameter
Jul 27, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8244 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via formMapDelDevice macstr Parameter
Jul 27, 2025
CVSS 8.8
EPSS 0.02
CVE-2025-8243 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via devicemac1 Parameter
Jul 27, 2025
CVSS 8.8
EPSS 0.02
CVE-2025-8242 HIGH
TOTOLINK X15 1.0.0-B20230714.1105 - Buffer Overflow via HTTP POST Request Handler
Jul 27, 2025
CVSS 8.8
EPSS 0.03
CVE-2025-8181 HIGH
TOTOLINK N600R/X2000R 1.0.0.1 - Privilege Escalation
Jul 26, 2025
CVSS 7.2
EPSS 0.01
CVE-2025-8170 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow in MQTT Packet Handler via tcpcheck_net serverIp Argument
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8140 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formWlanMultipleAP HTTP POST Request Handler
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8139 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formPortFw service_type Parameter
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8138 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formOneKeyAccessButton submit-url Parameter
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8137 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via HTTP POST Request Handler
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8136 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formFilter ip6addr Parameter
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7952 MEDIUM
TOTOLINK T6 4.1.5cu.748 - Command Injection
Jul 22, 2025
CVSS 6.3
EPSS 0.08
CVE-2025-44655 CRITICAL
TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9 - Privilege Escalation via vsftpd chroot_local_user Misconfiguration
Jul 21, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-7913 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 21, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7912 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 20, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7862 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Missing Authentication
Jul 20, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-7837 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 19, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7758 HIGH
TOTOLINK T6 <4.1.5cu.748_B20211015 - Buffer Overflow
Jul 17, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-52046 CRITICAL
Totolink A3300R V17.0.0cu.596_B20250515 - Unauthenticated Command Injection via mac and desc Parameters
Jul 17, 2025
CVSS 9.8
EPSS 0.62
CVE-2025-51630 CRITICAL
TOTOLINK N350RT V9.3.5u.6139_B20201216 - Buffer Overflow via ePort Parameter in setIpPortFilterRules
Jul 17, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-7615 MEDIUM
TOTOLINK T6 4.1.5cu.748 - Command Injection
Jul 14, 2025
CVSS 6.3
EPSS 0.05