Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ex1800t Firmware CRITICAL 9.8
CVE-2023-51021

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg in…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51022

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg …

No fix yet
Fix from $2,300 2023-12-22
Ex1200l Firmware CRITICAL 9.8
CVE-2023-51033

TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface.

No fix yet
Fix from $2,300 2023-12-22
Ex1200l Firmware CRITICAL 9.8
CVE-2023-51034

TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.

No fix yet
Fix from $2,300 2023-12-22
Ex1200l Firmware CRITICAL 9.8
CVE-2023-51035

TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.

No fix yet
Fix from $2,300 2023-12-22
A3700r Firmware CRITICAL 9.8
CVE-2023-50147

There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51023

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘host_time’ parameter of the NTPSyncWithHost interface o…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51024

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘tz’ parameter of the setNtpCfg interface o…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51025

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCf…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51026

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg in…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51027

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘apcliAuthMode’ parameter of the setWiFiExt…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51028

TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtende…

No fix yet
Fix from $2,300 2023-12-22
A7100ru Firmware CRITICAL 9.8
CVE-2023-6906

A vulnerability, which was classified as critical, was found in Totolink A7100RU 7.4cu.2313_B20191024. Affected is the function main of the file /cgi…

No fix yet
Fix from $2,300 2023-12-18
A7000r Firmware CRITICAL 9.8
CVE-2023-49417

TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.

No fix yet
Fix from $2,300 2023-12-11
A7000r Firmware CRITICAL 9.8
CVE-2023-49418

TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules.

No fix yet
Fix from $2,300 2023-12-11
X5000r Firmware CRITICAL 9.8
CVE-2023-6612EPSS 31%

A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDyn…

No fix yet
Fix from $2,300 2023-12-08
N300rt Firmware CRITICAL 9.8
CVE-2023-48860

TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end sec…

No fix yet
Fix from $2,300 2023-12-07
A3002ru Firmware HIGH 8.8
CVE-2023-48859

TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end sec…

No fix yet
Fix from $1,950 2023-12-06
X6000r Firmware CRITICAL 9.8
CVE-2023-48799

TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.

No fix yet
Fix from $2,300 2023-12-04
X6000r Firmware CRITICAL 9.8
CVE-2023-48800

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the …

No fix yet
Fix from $2,300 2023-12-04
X6000r Firmware CRITICAL 9.8
CVE-2023-48801

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the …

No fix yet
Fix from $2,300 2023-12-01
X6000r Firmware CRITICAL 9.8
CVE-2023-43453

An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter…

No fix yet
Fix from $2,300 2023-12-01
X6000r Firmware CRITICAL 9.8
CVE-2023-43454

An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName par…

No fix yet
Fix from $2,300 2023-12-01
X6000r Firmware CRITICAL 9.8
CVE-2023-43455

An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command para…

No fix yet
Fix from $2,300 2023-12-01
X6000r Firmware CRITICAL 9.8
CVE-2023-48808

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48810

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48811

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48812

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function t…

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48802

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30
X6000r Firmware CRITICAL 9.8
CVE-2023-48803

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function …

No fix yet
Fix from $2,300 2023-11-30