Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lr350 Firmware HIGH 7.5
CVE-2025-63468

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnera…

No fix yet
Fix from $1,950 2025-10-31
Lr350 Firmware HIGH 7.5
CVE-2025-63469

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerabilit…

No fix yet
Fix from $1,950 2025-10-31
Lr350 Firmware HIGH 7.5
CVE-2025-63466

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerab…

No fix yet
Fix from $1,950 2025-10-31
Lr350 Firmware HIGH 7.5
CVE-2025-63467

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerabilit…

No fix yet
Fix from $1,950 2025-10-31
A3300r Firmware HIGH 8.8
CVE-2025-12258

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. Impacted is the function setOpModeCfg of the file /cgi-bin/cstecgi.cg of the …

No fix yet
Fix from $1,950 2025-10-27
A3300r Firmware HIGH 8.8
CVE-2025-12259

A flaw has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi…

No fix yet
Fix from $1,950 2025-10-27
A3300r Firmware HIGH 8.8
CVE-2025-12260

A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setSyslogCfg of the file /cgi-bin/cste…

No fix yet
Fix from $1,950 2025-10-27
A3300r Firmware CRITICAL 9.8
CVE-2025-12239

A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setDdnsCfg of the file /cgi-bin/cstecg…

Mitigation only
Fix from $2,300 2025-10-27
A3300r Firmware CRITICAL 9.8
CVE-2025-12240

A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCfg of the file /cgi-bin/cstecg…

Mitigation only
Fix from $2,300 2025-10-27
A3300r Firmware HIGH 8.8
CVE-2025-12241

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This impacts the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of …

No fix yet
Fix from $1,950 2025-10-27
N600r Firmware HIGH 7.5
CVE-2025-60336

A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) v…

No fix yet
Fix from $1,950 2025-10-22
N600r Firmware HIGH 7.5
CVE-2025-60335

A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a c…

No fix yet
Fix from $1,950 2025-10-22
N600r Firmware HIGH 7.5
CVE-2025-60333

TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. Thi…

No fix yet
Fix from $1,950 2025-10-22
N600r Firmware HIGH 7.5
CVE-2025-60334

TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vuln…

No fix yet
Fix from $1,950 2025-10-22
N600r Firmware HIGH 8.8
CVE-2025-11444

A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /…

Fix: after 4.3.0cu.7866_b2022506
Fix from $1,950 2025-10-08
X18 Firmware CRITICAL 9.8
CVE-2025-61044

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentC…

Mitigation only
Fix from $2,300 2025-10-01
X18 Firmware CRITICAL 9.8
CVE-2025-61045

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg fun…

Mitigation only
Fix from $2,300 2025-10-01
X6000r Firmware CRITICAL 9.8
CVE-2025-11005

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti…

Fix: after 9.4.0cu.1360_b20241207
Fix from $2,300 2025-09-25
N600r Firmware MEDIUM 5.3
CVE-2025-57623

A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.

No fix yet
Fix from $1,600 2025-09-25
X6000r Firmware HIGH 8.8
CVE-2025-52907

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.13…

Fix: after 9.4.0cu.1360_b20241207
Fix from $1,950 2025-09-24
X6000r Firmware CRITICAL 9.8
CVE-2025-52906EPSS 13%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti…

Fix: after 9.4.0cu.1360_b20241207
Fix from $2,300 2025-09-24
X6000r Firmware HIGH 7.5
CVE-2025-52905EPSS 8%

Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Fix: after 9.4.0cu.1360_b20241207
Fix from $1,950 2025-09-23
X6000r Firmware CRITICAL 9.8
CVE-2025-52053

TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter…

Mitigation only
Fix from $2,300 2025-09-15
X2000r Firmware HIGH 8.0
CVE-2025-57579

An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password

No fix yet
Fix from $1,950 2025-09-12
X5000r Firmware CRITICAL 9.8
CVE-2025-9934

A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performin…

Mitigation only
Fix from $2,300 2025-09-04
N600r Firmware CRITICAL 9.8
CVE-2025-9935

A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi…

Mitigation only
Fix from $2,300 2025-09-04
A702r Firmware HIGH 8.8
CVE-2025-9783

A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the file /boafrm/formParentContr…

No fix yet
Fix from $1,950 2025-09-01
A702r Firmware HIGH 8.8
CVE-2025-9782

A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of the file /boafrm/formOneKeyAc…

No fix yet
Fix from $1,950 2025-09-01
A702r Firmware HIGH 8.8
CVE-2025-9781

A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file /boafrm/formFilter. Such mani…

No fix yet
Fix from $1,950 2025-09-01
A702r Firmware HIGH 8.8
CVE-2025-9779

A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_4162DC of the file /boafrm/fo…

No fix yet
Fix from $1,950 2025-09-01