Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ex1800t Firmware CRITICAL 9.8
CVE-2025-1852

A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAu…

Mitigation only
Fix from $2,300 2025-03-03
X18 Firmware HIGH 8.8
CVE-2025-1829EPSS 12%

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknat…

No fix yet
Fix from $1,950 2025-03-02
A3002r Firmware HIGH 8.0
CVE-2025-25610

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the st…

Mitigation only
Fix from $1,950 2025-02-28
A3002r Firmware HIGH 8.0
CVE-2025-25635

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pp…

No fix yet
Fix from $1,950 2025-02-28
A3002r Firmware HIGH 8.0
CVE-2025-25609

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the st…

Mitigation only
Fix from $1,950 2025-02-28
X5000r Firmware MEDIUM 6.5
CVE-2025-25604

Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.

No fix yet
Fix from $1,600 2025-02-21
X5000r Firmware MEDIUM 6.5
CVE-2025-25605

Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.

No fix yet
Fix from $1,600 2025-02-21
X18 Firmware HIGH 8.8
CVE-2025-1340EPSS 17%

A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cg…

Mitigation only
Fix from $1,950 2025-02-16
X18 Firmware HIGH 8.8
CVE-2025-1339

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been rated as critical. This issue affects the function setL2tpdConfig of th…

Mitigation only
Fix from $1,950 2025-02-16
X6000r Firmware MEDIUM 5.1
CVE-2025-25524

Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addit…

Mitigation only
Fix from $1,600 2025-02-11
A810r Firmware HIGH 8.1
CVE-2024-57036

TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability a…

No fix yet
Fix from $1,950 2025-01-21
X5000r Firmware HIGH 8.8
CVE-2024-57022

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleC…

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware MEDIUM 6.8
CVE-2024-57023

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCf…

No fix yet
Fix from $1,600 2025-01-15
X5000r Firmware MEDIUM 6.8
CVE-2024-57024

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiSchedul…

No fix yet
Fix from $1,600 2025-01-15
X5000r Firmware MEDIUM 6.8
CVE-2024-57025

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCf…

No fix yet
Fix from $1,600 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57011

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57012

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57013

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57014

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57015

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57016

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57017

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57018

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57019

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg.

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57020

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiSchedul…

No fix yet
Fix from $1,950 2025-01-15
X5000r Firmware HIGH 8.8
CVE-2024-57021

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleC…

No fix yet
Fix from $1,950 2025-01-15
A6000r Firmware MEDIUM 6.3
CVE-2024-57213

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd fu…

No fix yet
Fix from $1,600 2025-01-10
A6000r Firmware MEDIUM 6.3
CVE-2024-57214

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi functio…

No fix yet
Fix from $1,600 2025-01-10
A6000r Firmware HIGH 8.0
CVE-2024-57211

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh funct…

No fix yet
Fix from $1,950 2025-01-10
A6000r Firmware MEDIUM 5.1
CVE-2024-57212

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot funct…

No fix yet
Fix from $1,600 2025-01-10