Vulnerability index

Browse CVEs

1,039 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

A3700r Firmware HIGH 7.8
CVE-2022-36465

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.

No fix yet
Fix from $1,950 2022-08-25
A3700r Firmware HIGH 7.8
CVE-2022-36466

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.

No fix yet
Fix from $1,950 2022-08-25
A3002ru Firmware CRITICAL 9.8
CVE-2022-35491

TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.

Mitigation only
Fix from $2,300 2022-08-10
A3600r Firmware CRITICAL 9.8
CVE-2022-34993

Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.

No fix yet
Fix from $2,300 2022-08-04
Ex300 V2 Firmware CRITICAL 9.8
CVE-2022-32449EPSS 19%

TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function.…

No fix yet
Fix from $2,300 2022-07-07
A830r Firmware HIGH 7.2
CVE-2022-28935

Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B…

No fix yet
Fix from $1,950 2022-07-06
T6 Firmware HIGH 7.5
CVE-2022-32045

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.

No fix yet
Fix from $1,950 2022-07-01
T6 Firmware HIGH 7.5
CVE-2022-32046

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.

No fix yet
Fix from $1,950 2022-07-01
T6 Firmware HIGH 7.5
CVE-2022-32047

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4.

No fix yet
Fix from $1,950 2022-07-01
T6 Firmware HIGH 7.5
CVE-2022-32048

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88.

No fix yet
Fix from $1,950 2022-07-01
T6 Firmware HIGH 7.5
CVE-2022-32049

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540.

No fix yet
Fix from $1,950 2022-07-01
T6 Firmware HIGH 7.5
CVE-2022-32050

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.

No fix yet
Fix from $1,950 2022-07-01
T6 Firmware HIGH 7.5
CVE-2022-32051

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN_004133…

No fix yet
Fix from $1,950 2022-07-01
T6 Firmware HIGH 7.5
CVE-2022-32052

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4.

No fix yet
Fix from $1,950 2022-07-01
T6 Firmware HIGH 7.5
CVE-2022-32053

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.

No fix yet
Fix from $1,950 2022-07-01
Ex1200t Firmware HIGH 7.5
CVE-2021-42893

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.

No fix yet
Fix from $1,950 2022-06-03
Ex1200t Firmware HIGH 7.5
CVE-2021-42891

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.

No fix yet
Fix from $1,950 2022-06-03
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42890

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control …

No fix yet
Fix from $2,300 2022-06-03
Ex1200t Firmware HIGH 7.5
CVE-2021-42889

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.

No fix yet
Fix from $1,950 2022-06-03
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42888

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control l…

No fix yet
Fix from $2,300 2022-06-03
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42887EPSS 45%

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

No fix yet
Fix from $2,300 2022-06-03
Ex1200t Firmware HIGH 7.5
CVE-2021-42886

TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without author…

No fix yet
Fix from $1,950 2022-06-03
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42884

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control th…

No fix yet
Fix from $2,300 2022-06-03
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42885

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can control dev…

No fix yet
Fix from $2,300 2022-06-03
Ex1200t Firmware HIGH 7.5
CVE-2021-42877

TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can rebo…

No fix yet
Fix from $1,950 2022-06-02
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42875

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.…

Mitigation only
Fix from $2,300 2022-06-02
Ex1200t Firmware CRITICAL 9.8
CVE-2021-42872EPSS 7%

TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.

Mitigation only
Fix from $2,300 2022-06-02
A3600r Firmware HIGH 7.5
CVE-2022-29377

Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows…

No fix yet
Fix from $1,950 2022-05-24
A3100r Firmware CRITICAL 9.8
CVE-2022-29644

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in…

No fix yet
Fix from $2,300 2022-05-18
A3100r Firmware CRITICAL 9.8
CVE-2022-29645

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component…

No fix yet
Fix from $2,300 2022-05-18