Vulnerability index

Browse CVEs

1,039 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

A3700r Firmware CRITICAL 9.8
CVE-2024-37634

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.

No fix yet
Fix from $2,300 2024-06-13
A3700r Firmware CRITICAL 9.8
CVE-2024-37635

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg

No fix yet
Fix from $2,300 2024-06-13
A3700r Firmware HIGH 8.8
CVE-2024-37631

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.

No fix yet
Fix from $1,950 2024-06-13
A3700r Firmware HIGH 8.8
CVE-2024-37633

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg

No fix yet
Fix from $1,950 2024-06-13
A3100r Firmware HIGH 7.5
CVE-2024-36650

TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/lib/cste_…

No fix yet
Fix from $1,950 2024-06-11
Cp300 Firmware CRITICAL 9.8
CVE-2024-36782

TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in …

Mitigation only
Fix from $2,300 2024-06-03
Lr350 Firmware CRITICAL 9.8
CVE-2024-36783

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.

Mitigation only
Fix from $2,300 2024-06-03
Cp900l Firmware MEDIUM 5.9
CVE-2024-35401

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFi…

Mitigation only
Fix from $1,600 2024-05-28
Cp900l Firmware CRITICAL 9.8
CVE-2024-35398

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules.

Mitigation only
Fix from $2,300 2024-05-28
Cp900l Firmware HIGH 8.8
CVE-2024-35397EPSS 15%

TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime …

Mitigation only
Fix from $1,950 2024-05-28
Cp900l Firmware HIGH 8.8
CVE-2024-35399

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth

Mitigation only
Fix from $1,950 2024-05-28
Cp900l Firmware MEDIUM 5.3
CVE-2024-35400

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules

Mitigation only
Fix from $1,600 2024-05-28
Nr1800x Firmware HIGH 8.8
CVE-2024-35388

TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode

Mitigation only
Fix from $1,950 2024-05-24
Lr350 Firmware CRITICAL 9.8
CVE-2024-35387EPSS 6%

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

Mitigation only
Fix from $2,300 2024-05-24
Cp900l Firmware CRITICAL 9.8
CVE-2024-35396

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attac…

Mitigation only
Fix from $2,300 2024-05-24
Cp900l Firmware HIGH 8.8
CVE-2024-35395

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to …

Mitigation only
Fix from $1,950 2024-05-24
X5000r Firmware CRITICAL 9.8
CVE-2024-32353

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer funct…

No fix yet
Fix from $2,300 2024-05-14
X5000r Firmware HIGH 8.8
CVE-2024-32352

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEna…

No fix yet
Fix from $1,950 2024-05-14
X5000r Firmware HIGH 8.0
CVE-2024-32355

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer f…

No fix yet
Fix from $1,950 2024-05-14
X5000r Firmware MEDIUM 6.0
CVE-2024-32354

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer fu…

No fix yet
Fix from $1,600 2024-05-14
X5000r Firmware HIGH 8.8
CVE-2024-32350

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" pa…

No fix yet
Fix from $1,950 2024-05-14
X5000r Firmware HIGH 8.8
CVE-2024-32351

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" paramet…

No fix yet
Fix from $1,950 2024-05-14
X5000r Firmware MEDIUM 6.0
CVE-2024-32349

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" paramet…

No fix yet
Fix from $1,600 2024-05-14
Lr350 Firmware CRITICAL 9.8
CVE-2024-35099

TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

Mitigation only
Fix from $2,300 2024-05-14
X5000r Firmware HIGH 8.8
CVE-2024-34921EPSS 9%

TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.

No fix yet
Fix from $1,950 2024-05-14
Lr350 Firmware HIGH 8.8
CVE-2024-34308

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.

Mitigation only
Fix from $1,950 2024-05-14
Cp450 Firmware CRITICAL 9.8
CVE-2024-34213

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.

No fix yet
Fix from $2,300 2024-05-14
Cp450 Firmware HIGH 8.6
CVE-2024-34219EPSS 21%

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in throug…

No fix yet
Fix from $1,950 2024-05-14
Cp450 Firmware HIGH 7.7
CVE-2024-34217

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.

No fix yet
Fix from $1,950 2024-05-14
Cp450 Firmware HIGH 7.3
CVE-2024-34212

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.

No fix yet
Fix from $1,950 2024-05-14