totolink

1,216 tracked vulnerabilities.

CVE-2024-7172 HIGH
TOTOLINK A3600R 4.1.2cu.5182_B20201102 - Buffer Overflow via http_host Argument in getSaveConfig
Jul 28, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-7171 MEDIUM
TOTOLINK A3600R 4.1.2cu.5182_B20201102 - OS Command Injection via NTPSyncWithHost hostTime Parameter
Jul 28, 2024
CVSS 6.3
EPSS 0.03
CVE-2024-7170 LOW
TOTOLINK A3000RU 5.9c.5185 - Use of Hard-Coded Password
Jul 28, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-7160 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - OS Command Injection via hostName Parameter
Jul 28, 2024
CVSS 6.3
EPSS 0.03
CVE-2024-7159 MEDIUM
TOTOLINK A3600R 4.1.2cu.5182_ - Hard-coded Password
Jul 28, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-7158 MEDIUM
TOTOLINK A3100R 4.1.2cu.5050_B20200504 - Command Injection via telnet_enabled Argument
Jul 28, 2024
CVSS 6.3
EPSS 0.02
CVE-2024-7157 HIGH
TOTOLINK A3100R 4.1.2cu.5050_B20200504 - Buffer Overflow via http_host Argument in getSaveConfig
Jul 28, 2024
CVSS 8.8
EPSS 0.08
CVE-2024-7156 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Information Disclosure via ExportSettings.sh
Jul 28, 2024
CVSS 5.3
EPSS 0.09
CVE-2024-7155 LOW
TOTOLINK A3300R 17.0.0cu.557_B20221024 - Info Disclosure
Jul 28, 2024
CVSS 2.5
EPSS 0.00
CVE-2024-7154 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in Password Reset Handler
Jul 28, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-41319 CRITICAL
TOTOLINK A6000R V1.0.1-B20201211.2000 - OS Command Injection via Webcmd Function
Jul 23, 2024
CVSS 9.8
EPSS 0.51
CVE-2024-41320 HIGH
TOTOLINK A6000R V1.0.1-B20201211.2000 - OS Command Injection via ifname Parameter
Jul 22, 2024
CVSS 8.8
EPSS 0.01
CVE-2024-41318 CRITICAL
TOTOLINK A6000R V1.0.1-B20201211.2000 - OS Command Injection via ifname Parameter
Jul 22, 2024
CVSS 9.8
EPSS 0.03
CVE-2024-41317 HIGH
TOTOLINK A6000R V1.0.1-B20201211.2000 - OS Command Injection via ifname Parameter in apcli_do_enr_pbc_wps
Jul 22, 2024
CVSS 8.0
EPSS 0.01
CVE-2024-41316 CRITICAL
TOTOLINK A6000R V1.0.1-B20201211.2000 - OS Command Injection via ifname Parameter
Jul 22, 2024
CVSS 9.8
EPSS 0.02
CVE-2024-41315 MEDIUM
TOTOLINK A6000R V1.0.1-B20201211.2000 - OS Command Injection via ifname Parameter in apcli_do_enr_pin_wps
Jul 22, 2024
CVSS 6.8
EPSS 0.00
CVE-2024-41314 MEDIUM
TOTOLINK A6000R V1.0.1-B20201211.2000 - OS Command Injection via iface Parameter in vif_disable Function
Jul 22, 2024
CVSS 6.8
EPSS 0.00
CVE-2024-37626 HIGH
TOTOLINK A6000R V1.0.1-B20201211.2000 - OS Command Injection via iface Parameter in vif_enable Function
Jun 20, 2024
CVSS 8.8
EPSS 0.02
CVE-2024-37640 HIGH
TOTOLINK A3700R V9.1.2u.6165_20211012 - Stack-based Buffer Overflow via ssid5g in setWiFiEasyGuestCfg
Jun 14, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-37639 HIGH
TOTOLINK A3700R V9.1.2u.6165_20211012 - Stack-based Buffer Overflow via eport in setIpPortFilterRules
Jun 14, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-37637 CRITICAL
TOTOLINK A3700R V9.1.2u.6165_20211012 - Stack Overflow in setWizardCfg via ssid5g
Jun 14, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-37635 CRITICAL
TOTOLINK A3700R V9.1.2u.6165_20211012 - Stack-based Buffer Overflow via SSID in setWiFiBasicCfg
Jun 13, 2024
CVSS 9.8
EPSS 0.02
CVE-2024-37634 CRITICAL
TOTOLINK A3700R V9.1.2u.6165_20211012 - Stack-based Buffer Overflow via SSID in setWiFiEasyCfg
Jun 13, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-37633 HIGH
TOTOLINK A3700R V9.1.2u.6165_20211012 - Stack-based Buffer Overflow via SSID in setWiFiGuestCfg
Jun 13, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-37632 CRITICAL
TOTOLINK A3700R V9.1.2u.6165_20211012 - Stack-based Buffer Overflow via loginAuth Password Parameter
Jun 13, 2024
CVSS 9.8
EPSS 0.01