Vulnerability index

Browse CVEs

1,039 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Lr350 Firmware HIGH 7.5
CVE-2025-63469

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerabilit…

No fix yet
Fix from $1,950 2025-10-31
Lr350 Firmware HIGH 7.5
CVE-2025-63466

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerab…

No fix yet
Fix from $1,950 2025-10-31
Lr350 Firmware HIGH 7.5
CVE-2025-63467

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerabilit…

No fix yet
Fix from $1,950 2025-10-31
A3300r Firmware HIGH 8.8
CVE-2025-12258

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. Impacted is the function setOpModeCfg of the file /cgi-bin/cstecgi.cg of the …

No fix yet
Fix from $1,950 2025-10-27
A3300r Firmware HIGH 8.8
CVE-2025-12259

A flaw has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi…

No fix yet
Fix from $1,950 2025-10-27
A3300r Firmware HIGH 8.8
CVE-2025-12260

A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setSyslogCfg of the file /cgi-bin/cste…

No fix yet
Fix from $1,950 2025-10-27
A3300r Firmware CRITICAL 9.8
CVE-2025-12239

A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setDdnsCfg of the file /cgi-bin/cstecg…

Mitigation only
Fix from $2,300 2025-10-27
A3300r Firmware CRITICAL 9.8
CVE-2025-12240

A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCfg of the file /cgi-bin/cstecg…

Mitigation only
Fix from $2,300 2025-10-27
A3300r Firmware HIGH 8.8
CVE-2025-12241

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This impacts the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of …

No fix yet
Fix from $1,950 2025-10-27
N600r Firmware HIGH 7.5
CVE-2025-60336

A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) v…

No fix yet
Fix from $1,950 2025-10-22
N600r Firmware HIGH 7.5
CVE-2025-60335

A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a c…

No fix yet
Fix from $1,950 2025-10-22
N600r Firmware HIGH 7.5
CVE-2025-60333

TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. Thi…

No fix yet
Fix from $1,950 2025-10-22
N600r Firmware HIGH 7.5
CVE-2025-60334

TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vuln…

No fix yet
Fix from $1,950 2025-10-22
X18 Firmware CRITICAL 9.8
CVE-2025-61044

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentC…

Mitigation only
Fix from $2,300 2025-10-01
X18 Firmware CRITICAL 9.8
CVE-2025-61045

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg fun…

Mitigation only
Fix from $2,300 2025-10-01
N600r Firmware MEDIUM 5.3
CVE-2025-57623

A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.

No fix yet
Fix from $1,600 2025-09-25
X6000r Firmware CRITICAL 9.8
CVE-2025-52053

TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter…

Mitigation only
Fix from $2,300 2025-09-15
X2000r Firmware HIGH 8.0
CVE-2025-57579

An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password

No fix yet
Fix from $1,950 2025-09-12
X5000r Firmware CRITICAL 9.8
CVE-2025-9934

A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performin…

Mitigation only
Fix from $2,300 2025-09-04
N600r Firmware CRITICAL 9.8
CVE-2025-9935

A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi…

Mitigation only
Fix from $2,300 2025-09-04
A702r Firmware HIGH 8.8
CVE-2025-9783

A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the file /boafrm/formParentContr…

No fix yet
Fix from $1,950 2025-09-01
A702r Firmware HIGH 8.8
CVE-2025-9782

A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of the file /boafrm/formOneKeyAc…

No fix yet
Fix from $1,950 2025-09-01
A702r Firmware HIGH 8.8
CVE-2025-9781

A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file /boafrm/formFilter. Such mani…

No fix yet
Fix from $1,950 2025-09-01
A702r Firmware HIGH 8.8
CVE-2025-9779

A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_4162DC of the file /boafrm/fo…

No fix yet
Fix from $1,950 2025-09-01
A702r Firmware HIGH 8.8
CVE-2025-9780

A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this issue is the function sub_419BE0 of the file /boafrm/formIpQoS. This m…

No fix yet
Fix from $1,950 2025-09-01
X2000r Firmware HIGH 7.0
CVE-2025-9577

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the…

No fix yet
Fix from $1,950 2025-08-28
T10 Firmware CRITICAL 9.8
CVE-2025-9533EPSS 9%

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulati…

Mitigation only
Fix from $2,300 2025-08-27
A720r Firmware CRITICAL 9.8
CVE-2025-9303

A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParentalRules of the file /cgi-bin/cs…

Mitigation only
Fix from $2,300 2025-08-21
A3002r Firmware CRITICAL 9.8
CVE-2025-55591EPSS 7%

TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoi…

Mitigation only
Fix from $2,300 2025-08-18
A3002r Firmware HIGH 7.5
CVE-2025-55588

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability al…

No fix yet
Fix from $1,950 2025-08-18