Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

A3100r Firmware HIGH 8.8
CVE-2024-7158

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been declared as critical. This vulnerability affects the function setTel…

No fix yet
Fix from $1,950 2024-07-28
A3100r Firmware HIGH 8.8
CVE-2024-7157EPSS 7%

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been classified as critical. This affects the function getSaveConfig of t…

No fix yet
Fix from $1,950 2024-07-28
A3700r Firmware HIGH 7.5
CVE-2024-7156EPSS 13%

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. Affected by this issue is some unknown functionalit…

No fix yet
Fix from $1,950 2024-07-28
A3700r Firmware HIGH 7.5
CVE-2024-7154

A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file…

No fix yet
Fix from $1,950 2024-07-28
A6000r Firmware CRITICAL 9.8
CVE-2024-41319EPSS 6%

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

No fix yet
Fix from $2,300 2024-07-23
A6000r Firmware CRITICAL 9.8
CVE-2024-41316

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps fu…

No fix yet
Fix from $2,300 2024-07-22
A6000r Firmware CRITICAL 9.8
CVE-2024-41318

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pinco…

No fix yet
Fix from $2,300 2024-07-22
A6000r Firmware HIGH 8.8
CVE-2024-41320

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info…

No fix yet
Fix from $1,950 2024-07-22
A6000r Firmware HIGH 8.0
CVE-2024-41317

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wp…

No fix yet
Fix from $1,950 2024-07-22
A6000r Firmware MEDIUM 6.8
CVE-2024-41314

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

No fix yet
Fix from $1,600 2024-07-22
A6000r Firmware MEDIUM 6.8
CVE-2024-41315

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wp…

No fix yet
Fix from $1,600 2024-07-22
A6000r Firmware HIGH 8.8
CVE-2024-37626

A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface paramete…

Mitigation only
Fix from $1,950 2024-06-20
A3700r Firmware HIGH 8.8
CVE-2024-37640

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.

No fix yet
Fix from $1,950 2024-06-14
A3700r Firmware CRITICAL 9.8
CVE-2024-37637

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.

No fix yet
Fix from $2,300 2024-06-14
A3700r Firmware HIGH 8.8
CVE-2024-37639

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.

No fix yet
Fix from $1,950 2024-06-14
A3700r Firmware CRITICAL 9.8
CVE-2024-37632

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .

No fix yet
Fix from $2,300 2024-06-13
A3700r Firmware CRITICAL 9.8
CVE-2024-37634

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.

No fix yet
Fix from $2,300 2024-06-13
A3700r Firmware CRITICAL 9.8
CVE-2024-37635

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg

No fix yet
Fix from $2,300 2024-06-13
A3700r Firmware HIGH 8.8
CVE-2024-37631

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.

No fix yet
Fix from $1,950 2024-06-13
A3700r Firmware HIGH 8.8
CVE-2024-37633

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg

No fix yet
Fix from $1,950 2024-06-13
A3100r Firmware HIGH 7.5
CVE-2024-36650

TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/lib/cste_…

No fix yet
Fix from $1,950 2024-06-11
Cp300 Firmware CRITICAL 9.8
CVE-2024-36782

TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in …

Mitigation only
Fix from $2,300 2024-06-03
Lr350 Firmware CRITICAL 9.8
CVE-2024-36783

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.

Mitigation only
Fix from $2,300 2024-06-03
Cp900l Firmware MEDIUM 5.9
CVE-2024-35401

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFi…

Mitigation only
Fix from $1,600 2024-05-28
Cp900l Firmware CRITICAL 9.8
CVE-2024-35398

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules.

Mitigation only
Fix from $2,300 2024-05-28
Cp900l Firmware HIGH 8.8
CVE-2024-35397EPSS 15%

TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime …

Mitigation only
Fix from $1,950 2024-05-28
Cp900l Firmware HIGH 8.8
CVE-2024-35399

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth

Mitigation only
Fix from $1,950 2024-05-28
Cp900l Firmware MEDIUM 5.3
CVE-2024-35400

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules

Mitigation only
Fix from $1,600 2024-05-28
Nr1800x Firmware HIGH 8.8
CVE-2024-35388

TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode

Mitigation only
Fix from $1,950 2024-05-24
Lr350 Firmware CRITICAL 9.8
CVE-2024-35387EPSS 6%

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

Mitigation only
Fix from $2,300 2024-05-24