totolink

1,219 tracked vulnerabilities.

CVE-2024-28403 MEDIUM
TOTOLINK X2000R < 1.0.0-b20231213.1013 - Cross-Site Scripting via VPN Page
Mar 15, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-28338 HIGH
TOTOLINK A8000RU V7.1cu.643_B20200521 - Unauthenticated Login Bypass via Session Cookie
Mar 12, 2024
CVSS 8.0
EPSS 0.00
CVE-2024-2353 HIGH
Totolink X6000R 9.4.0cu.852_20230719 - Unauthenticated OS Command Injection via setDiagnosisCfg ip Parameter
Mar 10, 2024
CVSS 8.8
EPSS 0.06
CVE-2024-1783 CRITICAL
Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810 - Stack-based Buffer Overflow via http_host Parameter
Feb 23, 2024
CVSS 9.8
EPSS 0.01
CVE-2024-1781 MEDIUM
Totolink X6000R AX3000 9.4.0cu.852_20230719 - Command Injection via setWizardCfg Function
Feb 23, 2024
CVSS 6.3
EPSS 0.18
CVE-2024-1661 LOW
Totolink X6000R 9.4.0cu.852_B20230719 - Use of Hard-coded Credentials in /etc/shadow
Feb 20, 2024
CVSS 2.5
EPSS 0.00
CVE-2024-25468 HIGH
TOTOLINK X5000R V.9.1.0u.6369_B20230113 - Denial of Service via NTPSyncWithHost host_time Parameter
Feb 17, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-24333 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setWiFiAclRules desc Parameter
Jan 30, 2024
CVSS 9.8
EPSS 0.03
CVE-2024-24332 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setUrlFilterRules URL Parameter
Jan 30, 2024
CVSS 9.8
EPSS 0.04
CVE-2024-24331 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setWiFiScheduleCfg enable Parameter
Jan 30, 2024
CVSS 9.8
EPSS 0.02
CVE-2024-24330 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setRemoteCfg Port or Enable Parameter
Jan 30, 2024
CVSS 9.8
EPSS 0.02
CVE-2024-24329 CRITICAL NUCLEI
TotoLink Router setPortForwardRules - Command Injection
Jan 30, 2024
CVSS 9.8
EPSS 0.83
CVE-2024-24328 CRITICAL NUCLEI
TotoLink Router setMacFilterRules - Command Injection
Jan 30, 2024
CVSS 9.8
EPSS 0.84
CVE-2024-24327 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via pppoePass Parameter
Jan 30, 2024
CVSS 9.8
EPSS 0.01
CVE-2024-24326 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via arpEnable Parameter
Jan 30, 2024
CVSS 9.8
EPSS 0.01
CVE-2024-24325 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setParentalRules enable Parameter
Jan 30, 2024
CVSS 9.8
EPSS 0.03
CVE-2024-24324 CRITICAL
TOTOLINK A8000RU v7.1cu.643_B20200521 - Use of Hard-coded Credentials
Jan 30, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-1004 HIGH
Totolink N200RE 9.3.5u.6139_B20201216 - Stack-based Buffer Overflow in loginAuth via http_host
Jan 29, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-1003 HIGH
Totolink N200RE 9.3.5u.6139_B20201216 - Stack-based Buffer Overflow in setLanguageCfg via lang Parameter
Jan 29, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-1002 HIGH
Totolink N200RE 9.3.5u.6139_B20201216 - Stack-based Buffer Overflow in setIpPortFilterRules via ePort Argument
Jan 29, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-1001 HIGH
Totolink N200RE 9.3.5u.6139_B20201216 - Stack-based Buffer Overflow in cstecgi.cgi main Function
Jan 29, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-1000 HIGH
Totolink N200RE 9.3.5u.6139_B20201216 - Stack-based Buffer Overflow in setTracerouteCfg
Jan 29, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-0999 HIGH
Totolink N200RE 9.3.5u.6139_B20201216 - Buffer Overflow
Jan 29, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-0998 HIGH
Totolink N200RE 9.3.5u.6139_B20201216 - Buffer Overflow
Jan 29, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-0997 HIGH
Totolink N200RE 9.3.5u.6139_B20201216 - Buffer Overflow
Jan 29, 2024
CVSS 7.2
EPSS 0.00