totolink

1,216 tracked vulnerabilities.

CVE-2025-28256 CRITICAL
TOTOLINK A3100R V4.1.2cu.5247_B20211129 - Remote Code Execution via setWebWlanIdx in wireless.so
Mar 28, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-28138 CRITICAL
TOTOLINK A800R V4.1.2cu.5137_B20200730 - Unauthenticated Remote Code Execution via NoticeUrl Parameter
Mar 27, 2025
CVSS 9.8
EPSS 0.04
CVE-2025-28135 HIGH
TOTOLINK A810R V4.1.2cu.5182_B20201026 - Stack-based Buffer Overflow in downloadFile.cgi
Mar 27, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-2688 MEDIUM
TOTOLINK A3000RU <5.9c.5185 - Improper Access Controls
Mar 24, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-2370 HIGH
TOTOLINK EX1800T < 9.1.0cu.2112_b20220316 - Stack-based Buffer Overflow via apcliSsid Argument
Mar 17, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-2369 HIGH
TOTOLINK EX1800T < 9.1.0cu.2112_b20220316 - Stack-based Buffer Overflow via admpass Parameter
Mar 17, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-2097 HIGH
TOTOLINK EX1800T 9.1.0cu.2112_B20220316 - Stack-based Buffer Overflow via loginpass Argument
Mar 07, 2025
CVSS 8.8
EPSS 0.07
CVE-2025-2096 MEDIUM
TOTOLINK EX1800T 9.1.0cu.2112_B20220316 - OS Command Injection via setRebootScheCfg mode Parameter
Mar 07, 2025
CVSS 6.3
EPSS 0.04
CVE-2025-2095 MEDIUM
TOTOLINK EX1800T 9.1.0cu.2112_B20220316 - OS Command Injection via setDmzCfg ip Parameter
Mar 07, 2025
CVSS 6.3
EPSS 0.03
CVE-2025-2094 MEDIUM
TOTOLINK EX1800T 9.1.0cu.2112_B20220316 - OS Command Injection via apcliKey Parameter
Mar 07, 2025
CVSS 6.3
EPSS 0.25
CVE-2025-1852 HIGH
Totolink EX1800T 9.1.0cu.2112_B20220316 - Buffer Overflow
Mar 03, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-1829 MEDIUM
TOTOLINK X18 9.1.0cu.2024_B20220329 - Code Injection
Mar 02, 2025
CVSS 6.3
EPSS 0.01
CVE-2025-25635 HIGH
TOTOlink A3002R V1.1.1-B20200824.0128 - Buffer Overflow via pppoe_dns1 Parameter
Feb 28, 2025
CVSS 8.0
EPSS 0.00
CVE-2025-25610 HIGH
TOTOlink A3002R V1.1.1-B20200824.0128 - Buffer Overflow via static_gw Parameter
Feb 28, 2025
CVSS 8.0
EPSS 0.00
CVE-2025-25609 HIGH
TOTOlink A3002R V1.1.1-B20200824.0128 - Buffer Overflow via static_ipv6 Parameter in formIpv6Setup
Feb 28, 2025
CVSS 8.0
EPSS 0.00
CVE-2025-25605 MEDIUM
Totolink X5000R V9.1.0u.6369_B20230113 - OS Command Injection via apcli_wps_gen_pincode Function
Feb 21, 2025
CVSS 6.5
EPSS 0.02
CVE-2025-25604 MEDIUM
Totolink X5000R V9.1.0u.6369_B20230113 - OS Command Injection via vif_disable Function
Feb 21, 2025
CVSS 6.5
EPSS 0.02
CVE-2025-1340 HIGH
TOTOLINK X18 9.1.0cu.2024_B20220329 - Stack-Based Buffer Overflow in setPasswordCfg
Feb 16, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-1339 MEDIUM
TOTOLINK X18 9.1.0cu.2024_B20220329 - OS Command Injection via setL2tpdConfig enable Parameter
Feb 16, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-25524 MEDIUM
TOTOLink X6000R V9.4.0cu.652_B20230116 - Buffer Overflow in Wi-Fi Filtering Rule Addition
Feb 11, 2025
CVSS 5.1
EPSS 0.00
CVE-2024-57036 HIGH
TOTOLINK A810R V4.1.2cu.5032_B20200407 - Command Injection
Jan 21, 2025
CVSS 8.1
EPSS 0.00
CVE-2024-57025 MEDIUM
TOTOLINK X5000R V9.1.0cu.2350_B20230313 - Command Injection
Jan 15, 2025
CVSS 6.8
EPSS 0.00
CVE-2024-57024 MEDIUM
TOTOLINK X5000R V9.1.0cu.2350_B20230313 - Command Injection
Jan 15, 2025
CVSS 6.8
EPSS 0.00
CVE-2024-57023 MEDIUM
TOTOLINK X5000R V9.1.0cu.2350_B20230313 - Command Injection
Jan 15, 2025
CVSS 6.8
EPSS 0.00
CVE-2024-57022 HIGH
TOTOLINK X5000R V9.1.0cu.2350_B20230313 - Command Injection
Jan 15, 2025
CVSS 8.8
EPSS 0.03