Filtered by vendor Totolink Subscriptions
Total 947 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-28135 1 Totolink 2 A810r, A810r Firmware 2025-04-15 7.5 High
TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi.
CVE-2025-28256 1 Totolink 2 A3100r, A3100r Firmware 2025-04-14 9.8 Critical
An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.
CVE-2024-54907 1 Totolink 2 A3002r, A3002r Firmware 2025-04-09 8.8 High
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
CVE-2024-31810 1 Totolink 2 Ex200, Ex200 Firmware 2025-04-09 9.8 Critical
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2024-33433 1 Totolink 2 X2000r, X2000r Firmware 2025-04-09 4.8 Medium
Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.
CVE-2024-34204 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 9.8 Critical
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.
CVE-2024-34205 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 7.3 High
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.
CVE-2024-34206 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 6.5 Medium
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.
CVE-2024-34207 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 8.8 High
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.
CVE-2024-34209 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 9.8 Critical
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.
CVE-2024-34210 1 Totolink 3 Cp450, Cp450 Firmware, Outdoor Cpe Cp450 2025-04-09 7.3 High
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.
CVE-2024-34211 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 8.8 High
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
CVE-2024-34212 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 7.3 High
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.
CVE-2024-34213 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 9.8 Critical
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.
CVE-2024-34215 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 7.3 High
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.
CVE-2024-34217 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-09 7.7 High
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.
CVE-2024-27521 1 Totolink 2 A3300r, A3300r Firmware 2025-04-08 8.0 High
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail, exploitation allows unauthenticated, remote attackers to execute arbitrary system commands with administrative privileges (i.e., as user "root").
CVE-2024-28404 1 Totolink 2 X2000r, X2000r Firmware 2025-04-08 8.0 High
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.
CVE-2024-28402 1 Totolink 2 X2000r, X2000r Firmware 2025-04-08 5.9 Medium
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
CVE-2025-2369 1 Totolink 2 Ex1800t, Ex1800t Firmware 2025-04-07 8.8 High
A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316. It has been classified as critical. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument admpass leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.