Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Total 747 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29209 1 Totolink 2 X18, X18 Firmware 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi.
CVE-2025-28137 1 Totolink 2 A810r, A810r Firmware 2025-04-29 N/A 9.8 CRITICAL
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28136 1 Totolink 2 A800r, A800r Firmware 2025-04-29 N/A 6.5 MEDIUM
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.
CVE-2025-29064 1 Totolink 2 X18, X18 Firmware 2025-04-29 N/A 9.8 CRITICAL
An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.
CVE-2025-25524 1 Totolink 2 X6000r, X6000r Firmware 2025-04-29 N/A 5.1 MEDIUM
Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
CVE-2024-57036 1 Totolink 2 A810r, A810r Firmware 2025-04-29 N/A 8.1 HIGH
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.
CVE-2025-28031 1 Totolink 1 A810r Firmware 2025-04-29 N/A 6.5 MEDIUM
TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.
CVE-2025-28030 1 Totolink 2 A810r, A810r Firmware 2025-04-29 N/A 8.8 HIGH
TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function.
CVE-2025-28024 1 Totolink 2 A810r, A810r Firmware 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi
CVE-2025-28032 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2025-04-29 N/A 7.3 HIGH
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm parameter.
CVE-2025-28033 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2025-04-29 N/A 7.3 HIGH
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpTo parameter.
CVE-2025-28034 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.
CVE-2025-28035 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28036 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28037 1 Totolink 4 A810r, A810r Firmware, A950rg and 1 more 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.
CVE-2025-28038 1 Totolink 2 Ex1200t, Ex1200t Firmware 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.
CVE-2025-28039 1 Totolink 2 Ex1200t, Ex1200t Firmware 2025-04-29 N/A 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.
CVE-2022-44844 1 Totolink 2 A7100ru, A7100ru Firmware 2025-04-29 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.
CVE-2022-44843 1 Totolink 2 A7100ru, A7100ru Firmware 2025-04-29 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.
CVE-2022-44252 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-25 N/A 9.8 CRITICAL
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.