totolink

1,215 tracked vulnerabilities.

CVE-2025-28037 CRITICAL
TOTOLINK A810R V4.1.2cu.5182_B20201026 & A950RG V4.1.2cu.5161_B20200903 - RCE via setDiagnosisCfg ipDomain
Apr 22, 2025
CVSS 9.8
EPSS 0.07
CVE-2025-28031 MEDIUM
TOTOLINK A810R V4.1.2cu.5182_B20201026 - Info Disclosure
Apr 22, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-28030 HIGH
TOTOLINK A810R V4.1.2cu.5182_B20201026 - Stack-based Buffer Overflow via setParentalRules Parameters
Apr 22, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-28024 CRITICAL
TOTOLINK A810R V4.1.2cu.5182_B20201026 - Buffer Overflow in cstecgi.cgi
Apr 22, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-28034 CRITICAL
TOTOLINK A800R/A810R/A830R/A950RG/A3000RU/A3100R - RCE via NTPSyncWithHost hostTime
Apr 22, 2025
CVSS 9.8
EPSS 0.06
CVE-2025-28033 HIGH
TOTOLINK A800R/A810R/A830R/A950RG/A3000RU/A3100R - Stack-based Buffer Overflow via setNoticeCfg IpTo Parameter
Apr 22, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-28032 HIGH
TOTOLINK A800R/A810R/A830R/A950RG/A3000RU/A3100R - Stack Overflow via setNoticeCfg IpForm
Apr 22, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-29209 CRITICAL
TOTOLINK X18 v9.1.0cu.2024_B20220329 - Unauthenticated OS Command Injection via enable Parameter
Apr 18, 2025
CVSS 9.8
EPSS 0.02
CVE-2025-3675 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setL2tpServerCfg
Apr 16, 2025
CVSS 5.3
EPSS 0.01
CVE-2025-3674 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUrlFilterRules Function
Apr 16, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-3668 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setScheduleCfg Function
Apr 16, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-3667 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUPnPCfg Function
Apr 16, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-3666 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setDdnsCfg Function
Apr 16, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-3665 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setSmartQosCfg
Apr 16, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-3664 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setWiFiEasyGuestCfg
Apr 16, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-3663 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in Password Handler
Apr 16, 2025
CVSS 5.3
EPSS 0.02
CVE-2025-22903 MEDIUM
TOTOLINK N600R V4.3.0cu.7647_B20210106 - Stack-based Buffer Overflow via setWiFiWpsConfig pin Parameter
Apr 15, 2025
CVSS 4.6
EPSS 0.00
CVE-2025-22900 CRITICAL
Totolink N600R v4.3.0cu.7647_B20210106 - Stack-based Buffer Overflow via setWanConfig macCloneMac Parameter
Apr 15, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-28137 CRITICAL
TOTOLINK A810R V4.1.2cu.5182_B20201026 - Unauthenticated Remote Code Execution via NoticeUrl Parameter
Apr 15, 2025
CVSS 9.8
EPSS 0.25
CVE-2025-28136 MEDIUM
TOTOLINK A800R V4.1.2cu.5137_B20200730 - Stack-based Buffer Overflow in downloadFile.cgi
Apr 15, 2025
CVSS 6.5
EPSS 0.01
CVE-2025-3249 MEDIUM
TOTOLINK A6000R 1.0.1-B20201211.2000 - Command Injection
Apr 04, 2025
CVSS 6.3
EPSS 0.06
CVE-2025-29064 CRITICAL
TOTOLINK X18 v.9.1.0cu.2024_B20220329 - Remote Code Execution via cstecgi.cgi sub_410E54 Function
Apr 03, 2025
CVSS 9.8
EPSS 0.03
CVE-2025-2955 MEDIUM
TOTOLINK A3000RU <5.9c.5185 - Improper Access Controls
Mar 30, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-25579 CRITICAL
TOTOLINK A3002R V4.0.0-B20230531.1404 - OS Command Injection via bandstr Parameter
Mar 28, 2025
CVSS 9.8
EPSS 0.33
CVE-2025-28256 CRITICAL
TOTOLINK A3100R V4.1.2cu.5247_B20211129 - Remote Code Execution via setWebWlanIdx in wireless.so
Mar 28, 2025
CVSS 9.8
EPSS 0.01