totolink

1,210 tracked vulnerabilities.

CVE-2025-8139 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formPortFw service_type Parameter
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8138 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formOneKeyAccessButton submit-url Parameter
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8137 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via HTTP POST Request Handler
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-8136 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via formFilter ip6addr Parameter
Jul 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7952 MEDIUM
TOTOLINK T6 4.1.5cu.748 - Command Injection
Jul 22, 2025
CVSS 6.3
EPSS 0.08
CVE-2025-44655 CRITICAL
TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9 - Privilege Escalation via vsftpd chroot_local_user Misconfiguration
Jul 21, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-7913 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 21, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7912 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 20, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7862 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Missing Authentication
Jul 20, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-7837 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 19, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-7758 HIGH
TOTOLINK T6 <4.1.5cu.748_B20211015 - Buffer Overflow
Jul 17, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-52046 CRITICAL
Totolink A3300R V17.0.0cu.596_B20250515 - Unauthenticated Command Injection via mac and desc Parameters
Jul 17, 2025
CVSS 9.8
EPSS 0.62
CVE-2025-51630 CRITICAL
TOTOLINK N350RT V9.3.5u.6139_B20201216 - Buffer Overflow via ePort Parameter in setIpPortFilterRules
Jul 17, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-7615 MEDIUM
TOTOLINK T6 4.1.5cu.748 - Command Injection
Jul 14, 2025
CVSS 6.3
EPSS 0.05
CVE-2025-7614 MEDIUM
TOTOLINK T6 4.1.5cu.748 - Command Injection
Jul 14, 2025
CVSS 6.3
EPSS 0.05
CVE-2025-7613 MEDIUM
TOTOLINK T6 4.1.5cu.748 - Command Injection
Jul 14, 2025
CVSS 6.3
EPSS 0.05
CVE-2025-7525 MEDIUM
TOTOLINK T6 4.1.5cu.748_B20211015 - Command Injection
Jul 13, 2025
CVSS 6.3
EPSS 0.04
CVE-2025-7524 MEDIUM
TOTOLINK T6 4.1.5cu.748_B20211015 - Command Injection
Jul 13, 2025
CVSS 6.3
EPSS 0.04
CVE-2025-7460 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Buffer Overflow
Jul 11, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-52089 HIGH
TOTOLINK N300RB Firmware 8.54 - Authenticated Remote Code Execution via Hidden Debug Interface
Jul 11, 2025
CVSS 8.8
EPSS 0.03
CVE-2025-7154 MEDIUM
TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216 - OS Command Injection via Hostname Parameter
Jul 08, 2025
CVSS 6.3
EPSS 0.06
CVE-2025-6953 HIGH
TOTOLINK A3002RU 3.0.0-B20230809.1615 - Buffer Overflow via submit-url Parameter
Jul 01, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-6940 HIGH
TOTOLINK A702R 4.0.0-B20230721.1521 - Buffer Overflow via HTTP POST Request Handler
Jul 01, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-6939 HIGH
TOTOLINK A3002RU 3.0.0-B20230809.1615 - Buffer Overflow via HTTP POST Request Handler
Jul 01, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-6916 HIGH
TOTOLINK T6 4.1.5cu.748_B20211015 - Missing Authentication via Form_Login
Jun 30, 2025
CVSS 8.8
EPSS 0.00