Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Total 1107 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-28022 1 Totolink 2 A810r, A810r Firmware 2026-06-17 N/A 7.3 HIGH
TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.
CVE-2025-28021 1 Totolink 2 A810r, A810r Firmware 2026-06-17 N/A 7.3 HIGH
TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi through the v14 and v3 parameters
CVE-2025-28020 1 Totolink 2 A800r, A800r Firmware 2026-06-17 N/A 7.3 HIGH
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.
CVE-2025-28019 1 Totolink 2 A800r, A800r Firmware 2026-06-17 N/A 7.3 HIGH
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component
CVE-2025-28018 1 Totolink 2 A800r, A800r Firmware 2026-06-17 N/A 7.3 HIGH
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.
CVE-2025-28017 1 Totolink 2 A800r, A800r Firmware 2026-06-17 N/A 6.5 MEDIUM
TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.
CVE-2025-25635 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 8.0 HIGH
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.
CVE-2025-25610 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 8.0 HIGH
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.
CVE-2025-25609 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 8.0 HIGH
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa
CVE-2025-25605 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 6.5 MEDIUM
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.
CVE-2025-25604 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 6.5 MEDIUM
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
CVE-2025-25579 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
CVE-2025-25524 1 Totolink 2 X6000r, X6000r Firmware 2026-06-17 N/A 5.1 MEDIUM
Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
CVE-2025-22903 1 Totolink 2 N600r, N600r Firmware 2026-06-17 N/A 4.6 MEDIUM
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.
CVE-2025-22900 1 Totolink 2 N600r, N600r Firmware 2026-06-17 N/A 9.8 CRITICAL
Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.
CVE-2025-1852 1 Totolink 2 Ex1800t, Ex1800t Firmware 2026-06-17 9.0 HIGH 8.8 HIGH
A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-1829 1 Totolink 2 X18, X18 Firmware 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknatCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mtkhnatEnable leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-1340 1 Totolink 2 X18, X18 Firmware 2026-06-17 9.0 HIGH 8.8 HIGH
A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation as part of String leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-1339 1 Totolink 2 X18, X18 Firmware 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been rated as critical. This issue affects the function setL2tpdConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-14964 1 Totolink 2 T10, T10 Firmware 2026-06-17 10.0 HIGH 9.8 CRITICAL
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument loginAuthUrl leads to stack-based buffer overflow. The attack may be performed from remote.