Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Total 1004 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-60336 1 Totolink 2 N600r, N600r Firmware 2025-10-24 N/A 7.5 HIGH
A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVE-2025-60333 1 Totolink 2 N600r, N600r Firmware 2025-10-24 N/A 7.5 HIGH
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-60334 1 Totolink 2 N600r, N600r Firmware 2025-10-24 N/A 7.5 HIGH
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-60335 1 Totolink 2 N600r, N600r Firmware 2025-10-24 N/A 7.5 HIGH
A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVE-2025-61045 1 Totolink 2 X18, X18 Firmware 2025-10-21 N/A 9.8 CRITICAL
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.
CVE-2025-61044 1 Totolink 2 X18, X18 Firmware 2025-10-16 N/A 9.8 CRITICAL
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function.
CVE-2025-11005 1 Totolink 2 X6000r, X6000r Firmware 2025-10-16 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.
CVE-2025-11444 1 Totolink 2 N600r, N600r Firmware 2025-10-14 9.0 HIGH 8.8 HIGH
A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the component HTTP Request Handler. Such manipulation of the argument wepkey leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
CVE-2025-52906 1 Totolink 2 X6000r, X6000r Firmware 2025-10-14 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
CVE-2025-52907 1 Totolink 2 X6000r, X6000r Firmware 2025-10-14 N/A 8.8 HIGH
Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
CVE-2025-8181 1 Totolink 4 N600r, N600r Firmware, X2000r and 1 more 2025-10-09 8.3 HIGH 7.2 HIGH
A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.conf of the component FTP Service. The manipulation leads to least privilege violation. It is possible to initiate the attack remotely.
CVE-2025-52905 1 Totolink 2 X6000r, X6000r Firmware 2025-10-08 N/A 7.5 HIGH
Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
CVE-2025-9303 1 Totolink 2 A720r, A720r Firmware 2025-10-06 9.0 HIGH 8.8 HIGH
A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument desc results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.
CVE-2025-8937 1 Totolink 2 N350r, N350r Firmware 2025-10-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in TOTOLINK N350R 1.2.3-B20130826. This vulnerability affects unknown code of the file /boafrm/formSysCmd. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-8938 1 Totolink 2 N350r, N350r Firmware 2025-10-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boafrm/formSysTel of the component Telnet Service. The manipulation of the argument TelEnabled leads to backdoor. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-57579 1 Totolink 2 X2000r, X2000r Firmware 2025-10-02 N/A 8.0 HIGH
An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password
CVE-2025-25635 1 Totolink 2 A3002r, A3002r Firmware 2025-10-02 N/A 8.0 HIGH
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.
CVE-2025-9934 1 Totolink 2 X5000r, X5000r Firmware 2025-09-29 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
CVE-2025-9935 1 Totolink 2 N600r, N600r Firmware 2025-09-29 7.5 HIGH 7.3 HIGH
A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi-bin/cstecgi.cgi. Executing manipulation can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-57623 1 Totolink 2 N600r, N600r Firmware 2025-09-29 N/A 5.3 MEDIUM
A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.