totolink Vulnerabilities and Affected Products
Vulnerabilities associated with cp450.
Products
Clear product- A8000RU50 vulnerabilities
- A7100RU42 vulnerabilities
- A3002RU33 vulnerabilities
- x2000r_firmware29 vulnerabilities
- A702R27 vulnerabilities
- x6000r_firmware27 vulnerabilities
- A3002R26 vulnerabilities
- x5000r_firmware26 vulnerabilities
- X1525 vulnerabilities
- A3300R20 vulnerabilities
- A3600R20 vulnerabilities
- EX1200T19 vulnerabilities
- a3600r_firmware17 vulnerabilities
- T616 vulnerabilities
- A3700R15 vulnerabilities
- ex200_firmware15 vulnerabilities
- N300RH15 vulnerabilities
- a3700r_firmware14 vulnerabilities
- AC1200 T814 vulnerabilities
- LR1200GB14 vulnerabilities
- LR35014 vulnerabilities
- N150RT14 vulnerabilities
- N200RE14 vulnerabilities
- cp45013 vulnerabilities
- ac1200_t8_firmware12 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-15271HIGH | TOTOLINK EX200 Web boa.conf least privilege violationA security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. The manipulation leads to least privilege violation. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitation is known to be difficult. | CVSS7.7v4.0 | EPSS0.407% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11554MEDIUM | TOTOLINK CP450 vsftpd vsftpd.conf least privilege violationA vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | CVSS5.3v4.0 | EPSS0.206% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7465HIGH | TOTOLINK CP450 cstecgi.cgi loginauth buffer overflowA vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747_B20191224. Affected is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273558 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CWE-120Aug 5, 2024 | CVSS8.7v4.0 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7332CRITICAL | TOTOLINK CP450 Telnet Service product.ini hard-coded passwordA vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did… | CVSS9.3v4.0 | EPSS20.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-34209CRITICAL | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function. CWE-121May 9, 2024 | CVSS9.8v3.1 | EPSS0.936% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34213CRITICAL | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function. CWE-121May 9, 2024 | CVSS9.8v3.1 | EPSS0.936% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34200HIGH | TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function. | CVSS8.8v3.1 | EPSS0.909% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34201HIGH | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function. CWE-121May 9, 2024 | CVSS7.3v3.1 | EPSS0.554% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34202MEDIUM | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function. CWE-121May 9, 2024 | CVSS6.5v3.1 | EPSS0.677% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34205HIGH | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function. CWE-78May 9, 2024 | CVSS7.3v3.1 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34215HIGH | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function. CWE-121May 9, 2024 | CVSS7.3v3.1 | EPSS0.554% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34212HIGH | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function. CWE-121May 9, 2024 | CVSS7.3v3.1 | EPSS0.554% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. CWE-77May 9, 2024 | CVSS3.8v3.1 | EPSS17.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |