Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

A7100ru Firmware CRITICAL 9.8
CVE-2022-48123

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setting/delSta…

No fix yet
Fix from $2,300 2023-01-20
A7100ru Firmware CRITICAL 9.8
CVE-2022-47853

TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root sh…

No fix yet
Fix from $2,300 2023-01-17
A7100ru Firmware CRITICAL 9.8
CVE-2022-46631

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWi…

No fix yet
Fix from $2,300 2022-12-15
A7100ru Firmware CRITICAL 9.8
CVE-2022-46634

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWi…

No fix yet
Fix from $2,300 2022-12-15
A7100ru Firmware CRITICAL 9.8
CVE-2022-44843

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnCl…

No fix yet
Fix from $2,300 2022-11-25
A7100ru Firmware CRITICAL 9.8
CVE-2022-44844

TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCf…

No fix yet
Fix from $2,300 2022-11-25
Lr350 Firmware HIGH 8.8
CVE-2022-44260

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.

No fix yet
Fix from $1,950 2022-11-23
Lr350 Firmware CRITICAL 9.8
CVE-2022-44249

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.

No fix yet
Fix from $2,300 2022-11-23
Lr350 Firmware CRITICAL 9.8
CVE-2022-44250

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.

No fix yet
Fix from $2,300 2022-11-23
Lr350 Firmware CRITICAL 9.8
CVE-2022-44251

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.

No fix yet
Fix from $2,300 2022-11-23
Lr350 Firmware CRITICAL 9.8
CVE-2022-44252

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.

No fix yet
Fix from $2,300 2022-11-23
Lr350 Firmware CRITICAL 9.8
CVE-2022-44255

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.

No fix yet
Fix from $2,300 2022-11-23
Lr350 Firmware HIGH 8.8
CVE-2022-44253

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.

No fix yet
Fix from $1,950 2022-11-23
Lr350 Firmware HIGH 8.8
CVE-2022-44254

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.

No fix yet
Fix from $1,950 2022-11-23
Nr1800x Firmware HIGH 8.8
CVE-2022-44256

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.

No fix yet
Fix from $1,950 2022-11-23
Lr350 Firmware HIGH 8.8
CVE-2022-44257

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.

No fix yet
Fix from $1,950 2022-11-23
Lr350 Firmware HIGH 8.8
CVE-2022-44258

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.

No fix yet
Fix from $1,950 2022-11-23
Lr350 Firmware HIGH 8.8
CVE-2022-44259

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules fun…

No fix yet
Fix from $1,950 2022-11-23
Nr1800x Firmware CRITICAL 9.8
CVE-2022-41525

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cg…

No fix yet
Fix from $2,300 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41526

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg functio…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41527

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg fun…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41528

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware CRITICAL 9.8
CVE-2022-41522

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.

No fix yet
Fix from $2,300 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41523

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg f…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41524

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the se…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41521

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilte…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41520

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule fu…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware CRITICAL 9.8
CVE-2022-41518

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/c…

No fix yet
Fix from $2,300 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41517

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

No fix yet
Fix from $1,950 2022-10-06
A860r Firmware CRITICAL 9.8
CVE-2022-40475

TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.

No fix yet
Fix from $2,300 2022-09-29