Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

A3002r Firmware HIGH 7.5
CVE-2024-33820

Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt fun…

No fix yet
Fix from $1,950 2024-05-01
N300rt Firmware MEDIUM 6.5
CVE-2024-32334

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.

No fix yet
Fix from $1,600 2024-04-18
N300rt Firmware MEDIUM 5.4
CVE-2024-32335

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.

No fix yet
Fix from $1,600 2024-04-18
Ex200 Firmware MEDIUM 6.8
CVE-2024-32326

TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig func…

No fix yet
Fix from $1,600 2024-04-18
N300rt Firmware MEDIUM 6.1
CVE-2024-32332

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page.

No fix yet
Fix from $1,600 2024-04-18
N300rt Firmware MEDIUM 5.5
CVE-2024-32327

TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.

No fix yet
Fix from $1,600 2024-04-18
X2000r Firmware MEDIUM 5.9
CVE-2024-28402

TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.

Fix: 1.0.0-b20231213.1013+
Fix from $1,600 2024-04-11
Ex200 Firmware HIGH 7.5
CVE-2024-31817EPSS 55%

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.

No fix yet
Fix from $1,950 2024-04-08
Ex200 Firmware CRITICAL 9.8
CVE-2024-31807

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSync…

No fix yet
Fix from $2,300 2024-04-08
Ex200 Firmware CRITICAL 9.1
CVE-2024-31815

In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

No fix yet
Fix from $2,300 2024-04-08
Ex200 Firmware HIGH 8.8
CVE-2024-31808

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWe…

No fix yet
Fix from $1,950 2024-04-08
Ex200 Firmware HIGH 8.8
CVE-2024-31809

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgr…

No fix yet
Fix from $1,950 2024-04-08
Ex200 Firmware HIGH 8.8
CVE-2024-31814EPSS 9%

TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.

No fix yet
Fix from $1,950 2024-04-08
Ex200 Firmware HIGH 8.4
CVE-2024-31813

TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.

Mitigation only
Fix from $1,950 2024-04-08
Ex200 Firmware HIGH 8.0
CVE-2024-31811

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLang…

No fix yet
Fix from $1,950 2024-04-08
Ex200 Firmware HIGH 7.5
CVE-2024-31816

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.

Mitigation only
Fix from $1,950 2024-04-08
Ex200 Firmware MEDIUM 6.5
CVE-2024-31805

TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setT…

No fix yet
Fix from $1,600 2024-04-08
Ex200 Firmware MEDIUM 6.5
CVE-2024-31806

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot…

Mitigation only
Fix from $1,600 2024-04-08
Ex200 Firmware MEDIUM 6.5
CVE-2024-31812

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConf…

Mitigation only
Fix from $1,600 2024-04-08
A3300r Firmware HIGH 8.0
CVE-2024-27521

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parame…

Mitigation only
Fix from $1,950 2024-03-26
X2000r Firmware MEDIUM 5.4
CVE-2024-29419

There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.101…

Fix: 1.0.0-b20231213.1013+
Fix from $1,600 2024-03-20
X5000r Firmware CRITICAL 9.8
CVE-2024-28639

Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrar…

No fix yet
Fix from $2,300 2024-03-16
X5000r Firmware HIGH 7.5
CVE-2024-28640EPSS 14%

Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial …

Mitigation only
Fix from $1,950 2024-03-16
X2000r Firmware HIGH 8.0
CVE-2024-28404

TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.

Fix: 1.0.0-b20231213.1013+
Fix from $1,950 2024-03-15
X2000r Firmware MEDIUM 5.4
CVE-2024-28401

TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.

Fix: 1.0.0-b20231213.1013+
Fix from $1,600 2024-03-15
X2000r Firmware MEDIUM 5.4
CVE-2024-28403

TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.

Fix: 1.0.0-b20231213.1013+
Fix from $1,600 2024-03-15
A8000ru Firmware HIGH 8.0
CVE-2024-28338

A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.

No fix yet
Fix from $1,950 2024-03-12
X6000r Firmware HIGH 8.8
CVE-2024-2353

A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnos…

No fix yet
Fix from $1,950 2024-03-10
Lr1200gb Firmware CRITICAL 9.8
CVE-2024-1783

A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810. Affected is the function logi…

No fix yet
Fix from $2,300 2024-02-23
X6000r Firmware CRITICAL 9.8
CVE-2024-1781EPSS 15%

A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg…

No fix yet
Fix from $2,300 2024-02-23