totolink

1,215 tracked vulnerabilities.

CVE-2025-45842 HIGH
TOTOLINK NR1800X V9.1.0u.6681_B20230703 - Authenticated Stack-based Buffer Overflow via ssid5g Parameter
May 08, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-45841 CRITICAL
TOTOLINK NR1800X V9.1.0u.6681_B20230703 - Authenticated Stack-based Buffer Overflow via setSmsCfg Text Parameter
May 08, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-4271 MEDIUM
TOTOLINK A720R 4.1.5cu.374 - Info Disclosure
May 05, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-4270 MEDIUM
TOTOLINK A720R 4.1.5cu.374 - Info Disclosure
May 05, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-4269 MEDIUM
TOTOLINK A720R 4.1.5cu.374 - Improper Access Controls
May 05, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-4268 MEDIUM
TOTOLINK A720R 4.1.5cu.374 - Auth Bypass
May 05, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-45800 CRITICAL
TOTOLINK A950RG V4.1.2cu.5204_B20210112 - OS Command Injection via setDeviceName deviceMac Parameter
May 02, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-44863 MEDIUM
TOTOLINK CA300-POE V6.2c.884_B20180522 - OS Command Injection via msg_process Url Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44862 MEDIUM
TOTOLINK CA300-POE V6.2c.884_B20180522 - OS Command Injection via recvUpgradeNewFw fwUrl Parameter
May 01, 2025
CVSS 6.3
EPSS 0.10
CVE-2025-44861 MEDIUM
TOTOLINK CA300-POE V6.2c.884_B20180522 - OS Command Injection via CloudSrvUserdataVersionCheck URL Parameter
May 01, 2025
CVSS 6.3
EPSS 0.10
CVE-2025-44860 MEDIUM
TOTOLINK CA300-POE V6.2c.884_B20180522 - OS Command Injection via msg_process Port Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44848 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via msg_process Url Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44847 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via setWebWlanIdx webWlanIdx Parameter
May 01, 2025
CVSS 6.3
EPSS 0.10
CVE-2025-44846 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via recvUpgradeNewFw fwUrl Parameter
May 01, 2025
CVSS 6.3
EPSS 0.10
CVE-2025-44845 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via NTPSyncWithHost hostTime Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44844 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via setUpgradeFW FileName Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44843 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via CloudSrvUserdataVersionCheck URL Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44842 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via msg_process Port Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44841 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via CloudSrvUserdataVersionCheck Version Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44840 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via CloudSrvUserdataVersionCheck svn Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44839 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 - OS Command Injection via CloudSrvUserdataVersionCheck magicid Parameter
May 01, 2025
CVSS 6.5
EPSS 0.09
CVE-2025-44838 MEDIUM
TOTOLINK CP900 V6.3c.1144_B20190715 - OS Command Injection via setUploadUserData FileName Parameter
May 01, 2025
CVSS 6.3
EPSS 0.10
CVE-2025-44837 MEDIUM
TOTOLINK CP900 V6.3c.1144_B20190715 - OS Command Injection via CloudSrvUserdataVersionCheck URL or MagicID Parameter
May 01, 2025
CVSS 6.3
EPSS 0.10
CVE-2025-44836 MEDIUM
TOTOLINK CP900 V6.3c.1144_B20190715 - OS Command Injection via setApRebootScheCfg Hour/Minute Parameters
May 01, 2025
CVSS 6.3
EPSS 0.10
CVE-2025-44854 MEDIUM
TOTOLINK CP900 V6.3c.1144_B20190715 - OS Command Injection via setUpgradeUboot FileName Parameter
May 01, 2025
CVSS 6.3
EPSS 0.10