Vulnerability index

Browse CVEs

1,039 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

A3700r Firmware MEDIUM 5.3
CVE-2025-3664

A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg o…

No fix yet
Fix from $1,600 2025-04-16
N600r Firmware CRITICAL 9.8
CVE-2025-22900

Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.

No fix yet
Fix from $2,300 2025-04-15
A810r Firmware CRITICAL 9.8
CVE-2025-28137EPSS 14%

The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function throu…

No fix yet
Fix from $2,300 2025-04-15
A800r Firmware MEDIUM 6.5
CVE-2025-28136

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.

Mitigation only
Fix from $1,600 2025-04-15
A6000r Firmware CRITICAL 9.8
CVE-2025-3249

A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel…

No fix yet
Fix from $2,300 2025-04-04
X18 Firmware CRITICAL 9.8
CVE-2025-29064

An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.

Mitigation only
Fix from $2,300 2025-04-03
A3002r Firmware CRITICAL 9.8
CVE-2025-25579EPSS 10%

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.

No fix yet
Fix from $2,300 2025-03-28
A3100r Firmware CRITICAL 9.8
CVE-2025-28256

An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_mo…

No fix yet
Fix from $2,300 2025-03-28
A800r Firmware CRITICAL 9.8
CVE-2025-28138

The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function throu…

No fix yet
Fix from $2,300 2025-03-27
A810r Firmware HIGH 7.5
CVE-2025-28135

TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi.

No fix yet
Fix from $1,950 2025-03-27
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2097EPSS 7%

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue affects the function setRptW…

No fix yet
Fix from $2,300 2025-03-07
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2095

A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cg…

No fix yet
Fix from $2,300 2025-03-07
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2096

A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg…

No fix yet
Fix from $2,300 2025-03-07
Ex1800t Firmware CRITICAL 9.8
CVE-2025-2094EPSS 13%

A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiEx…

No fix yet
Fix from $2,300 2025-03-07
Ex1800t Firmware CRITICAL 9.8
CVE-2025-1852

A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAu…

Mitigation only
Fix from $2,300 2025-03-03
X18 Firmware HIGH 8.8
CVE-2025-1829EPSS 12%

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknat…

No fix yet
Fix from $1,950 2025-03-02
A3002r Firmware HIGH 8.0
CVE-2025-25610

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the st…

Mitigation only
Fix from $1,950 2025-02-28
A3002r Firmware HIGH 8.0
CVE-2025-25635

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pp…

No fix yet
Fix from $1,950 2025-02-28
A3002r Firmware HIGH 8.0
CVE-2025-25609

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the st…

Mitigation only
Fix from $1,950 2025-02-28
X5000r Firmware MEDIUM 6.5
CVE-2025-25604

Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.

No fix yet
Fix from $1,600 2025-02-21
X5000r Firmware MEDIUM 6.5
CVE-2025-25605

Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.

No fix yet
Fix from $1,600 2025-02-21
X18 Firmware HIGH 8.8
CVE-2025-1340EPSS 17%

A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cg…

Mitigation only
Fix from $1,950 2025-02-16
X18 Firmware HIGH 8.8
CVE-2025-1339

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been rated as critical. This issue affects the function setL2tpdConfig of th…

Mitigation only
Fix from $1,950 2025-02-16
X6000r Firmware MEDIUM 5.1
CVE-2025-25524

Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addit…

Mitigation only
Fix from $1,600 2025-02-11
A810r Firmware HIGH 8.1
CVE-2024-57036

TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability a…

No fix yet
Fix from $1,950 2025-01-21
X5000r Firmware HIGH 8.8
CVE-2024-57022

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleC…

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware MEDIUM 6.8
CVE-2024-57023

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCf…

No fix yet
Fix from $1,600 2025-01-15
X5000r Firmware MEDIUM 6.8
CVE-2024-57024

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiSchedul…

No fix yet
Fix from $1,600 2025-01-15
X5000r Firmware MEDIUM 6.8
CVE-2024-57025

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCf…

No fix yet
Fix from $1,600 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57011

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15