Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nr1800x Firmware CRITICAL 9.8
CVE-2026-5030

A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecg…

Mitigation only
Fix from $2,300 2026-03-29
A3600r Firmware CRITICAL 9.8
CVE-2026-5020

A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cste…

Mitigation only
Fix from $2,300 2026-03-29
Lr350 Firmware HIGH 8.8
CVE-2026-4976

A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstec…

No fix yet
Fix from $1,950 2026-03-27
X6000r Firmware HIGH 8.8
CVE-2026-4611

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file …

Mitigation only
Fix from $1,950 2026-03-23
Wa300 Firmware CRITICAL 9.8
CVE-2026-4497

A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/c…

Mitigation only
Fix from $2,300 2026-03-20
N300rh Firmware CRITICAL 9.8
CVE-2026-3696

A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $2,300 2026-03-08
N300rh Firmware CRITICAL 9.8
CVE-2026-3301

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file …

Mitigation only
Fix from $2,300 2026-02-27
X5000r Firmware HIGH 7.5
CVE-2025-67445

TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environm…

No fix yet
Fix from $1,950 2026-02-24
X5000r Firmware CRITICAL 9.8
CVE-2025-70327

TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executa…

Mitigation only
Fix from $2,300 2026-02-23
X6000r Firmware HIGH 8.8
CVE-2025-70328

TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executa…

No fix yet
Fix from $1,950 2026-02-23
X5000r Firmware HIGH 8.0
CVE-2025-70329

TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable…

No fix yet
Fix from $1,950 2026-02-23
A3002ru Firmware HIGH 8.8
CVE-2026-26731

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 functio…

No fix yet
Fix from $1,950 2026-02-17
A3002ru Firmware HIGH 8.8
CVE-2026-26732

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the form…

No fix yet
Fix from $1,950 2026-02-17
A3002ru Firmware HIGH 8.8
CVE-2026-26736

TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup …

Fix: after 3.0.0-b20220304.1804
Fix from $1,950 2026-02-17
Wa300 Firmware HIGH 8.8
CVE-2026-2167

A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.c…

No fix yet
Fix from $1,950 2026-02-08
A950rg Firmware CRITICAL 9.8
CVE-2025-67186

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /lib/cste_modules/firewall.so.…

Mitigation only
Fix from $2,300 2026-02-03
A950rg Firmware CRITICAL 9.8
CVE-2025-67187

A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists in the setIpQosRules interface…

Mitigation only
Fix from $2,300 2026-02-03
A950rg Firmware CRITICAL 9.8
CVE-2025-67188

A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg interface of the /lib/cste_mo…

Mitigation only
Fix from $2,300 2026-02-03
A950rg Firmware MEDIUM 6.5
CVE-2025-67189

A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The urlKeyword parameter is not …

No fix yet
Fix from $1,600 2026-02-03
A3600r Firmware HIGH 8.8
CVE-2026-1686

A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig in the library /lib/cste_mod…

No fix yet
Fix from $1,950 2026-01-30
A7000r Firmware MEDIUM 6.3
CVE-2026-1623

A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulati…

No fix yet
Fix from $1,600 2026-01-29
A7000r Firmware MEDIUM 6.3
CVE-2026-1601

A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi…

No fix yet
Fix from $1,600 2026-01-29
A7000r Firmware HIGH 8.8
CVE-2026-1548

A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This man…

No fix yet
Fix from $1,950 2026-01-28
A7000r Firmware CRITICAL 9.8
CVE-2026-1547

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipul…

Mitigation only
Fix from $2,300 2026-01-28
Nr1800x Firmware HIGH 8.8
CVE-2026-1328

A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. Impacted is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the…

No fix yet
Fix from $1,950 2026-01-22
Nr1800x Firmware HIGH 8.8
CVE-2026-1326

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cste…

No fix yet
Fix from $1,950 2026-01-22
Nr1800x Firmware HIGH 8.8
CVE-2026-1327

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /c…

No fix yet
Fix from $1,950 2026-01-22
Lr350 Firmware HIGH 8.8
CVE-2026-1158

A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bi…

No fix yet
Fix from $1,950 2026-01-19
Lr350 Firmware HIGH 8.8
CVE-2026-1157

A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Su…

No fix yet
Fix from $1,950 2026-01-19
Lr350 Firmware HIGH 8.8
CVE-2026-1156

A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/c…

No fix yet
Fix from $1,950 2026-01-19