Vulnerability index

Browse CVEs

1,039 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

A7100ru Firmware CRITICAL 9.8
CVE-2022-28580

It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whi…

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28581

It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, w…

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28582

It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whi…

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28583

It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which …

No fix yet
Fix from $2,300 2022-05-05
A7100ru Firmware CRITICAL 9.8
CVE-2022-28584

It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, whic…

No fix yet
Fix from $2,300 2022-05-05
N200re Firmware MEDIUM 6.1
CVE-2020-23617

A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scri…

Mitigation only
Fix from $1,600 2022-05-02
Ex300 V2 Firmware HIGH 7.5
CVE-2021-43663

totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.

No fix yet
Fix from $1,950 2022-03-31
Ex300 V2 Firmware MEDIUM 6.5
CVE-2021-43662

totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.

No fix yet
Fix from $1,600 2022-03-31
Ex300 V2 Firmware MEDIUM 6.1
CVE-2021-43661

totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.

No fix yet
Fix from $1,600 2022-03-31
Ex300 V2 Firmware HIGH 8.8
CVE-2022-25008

totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.

No fix yet
Fix from $1,950 2022-03-30
Ar3100r Firmware CRITICAL 9.8
CVE-2021-46007

totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not…

Mitigation only
Fix from $2,300 2022-03-30
A3100r Firmware CRITICAL 9.8
CVE-2021-46009EPSS 13%

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set…

Mitigation only
Fix from $2,300 2022-03-30
A3100r Firmware HIGH 8.8
CVE-2021-46008

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to th…

Mitigation only
Fix from $1,950 2022-03-30
A3100r Firmware HIGH 8.8
CVE-2021-46010

Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can…

Mitigation only
Fix from $1,950 2022-03-30
Ex300 V2 Firmware HIGH 8.1
CVE-2021-43664

totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.

No fix yet
Fix from $1,950 2022-03-30
A3100r Firmware MEDIUM 6.5
CVE-2021-46006EPSS 5%

In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure m…

No fix yet
Fix from $1,600 2022-03-30
T10 V2 Firmware CRITICAL 9.8
CVE-2021-43636

Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function when processing host data in…

Mitigation only
Fix from $2,300 2022-03-25
N600r Firmware CRITICAL 9.8
CVE-2022-26186

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.

No fix yet
Fix from $2,300 2022-03-22
N600r Firmware CRITICAL 9.8
CVE-2022-26187EPSS 20%

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.

No fix yet
Fix from $2,300 2022-03-22
N600r Firmware CRITICAL 9.8
CVE-2022-26188

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.

No fix yet
Fix from $2,300 2022-03-22
N600r Firmware CRITICAL 9.8
CVE-2022-26189

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.

No fix yet
Fix from $2,300 2022-03-22
X5000r Firmware CRITICAL 9.8
CVE-2022-27003

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in th…

No fix yet
Fix from $2,300 2022-03-15
X5000r Firmware CRITICAL 9.8
CVE-2022-27004

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in th…

No fix yet
Fix from $2,300 2022-03-15
X5000r Firmware CRITICAL 9.8
CVE-2022-27005EPSS 5%

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in th…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26206

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26207

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26208

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26209

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26210EPSS 6%

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15
A830r Firmware CRITICAL 9.8
CVE-2022-26211

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…

No fix yet
Fix from $2,300 2022-03-15