Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-33820
Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt fun…
A3002r Firmware
No fix yet
MEDIUM 6.5
CVE-2024-32334
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
N300rt Firmware
No fix yet
MEDIUM 5.4
CVE-2024-32335
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.
N300rt Firmware
No fix yet
MEDIUM 6.8
CVE-2024-32326
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig func…
Ex200 Firmware
No fix yet
MEDIUM 6.1
CVE-2024-32332
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page.
N300rt Firmware
No fix yet
MEDIUM 5.5
CVE-2024-32327
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.
N300rt Firmware
No fix yet
MEDIUM 5.9
CVE-2024-28402
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
X2000r Firmware
1.0.0-b20231213.1013+
HIGH 7.5
CVE-2024-31817EPSS 55%
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
Ex200 Firmware
No fix yet
CRITICAL 9.8
CVE-2024-31807
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSync…
Ex200 Firmware
No fix yet
CRITICAL 9.1
CVE-2024-31815
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
Ex200 Firmware
No fix yet
HIGH 8.8
CVE-2024-31808
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWe…
Ex200 Firmware
No fix yet
HIGH 8.8
CVE-2024-31809
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgr…
Ex200 Firmware
No fix yet
HIGH 8.8
CVE-2024-31814EPSS 9%
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.
Ex200 Firmware
No fix yet
HIGH 8.4
CVE-2024-31813
TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.
Ex200 Firmware
Mitigation only
HIGH 8.0
CVE-2024-31811
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLang…
Ex200 Firmware
No fix yet
HIGH 7.5
CVE-2024-31816
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.
Ex200 Firmware
Mitigation only
MEDIUM 6.5
CVE-2024-31805
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setT…
Ex200 Firmware
No fix yet
MEDIUM 6.5
CVE-2024-31806
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot…
Ex200 Firmware
Mitigation only
MEDIUM 6.5
CVE-2024-31812
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConf…
Ex200 Firmware
Mitigation only
HIGH 8.0
CVE-2024-27521
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parame…
A3300r Firmware
Mitigation only
MEDIUM 5.4
CVE-2024-29419
There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.101…
X2000r Firmware
1.0.0-b20231213.1013+
CRITICAL 9.8
CVE-2024-28639
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrar…
X5000r Firmware
No fix yet
HIGH 7.5
CVE-2024-28640EPSS 14%
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial …
X5000r Firmware
Mitigation only
HIGH 8.0
CVE-2024-28404
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.
X2000r Firmware
1.0.0-b20231213.1013+
MEDIUM 5.4
CVE-2024-28401
TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.
X2000r Firmware
1.0.0-b20231213.1013+
MEDIUM 5.4
CVE-2024-28403
TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.
X2000r Firmware
1.0.0-b20231213.1013+
HIGH 8.0
CVE-2024-28338
A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.
A8000ru Firmware
No fix yet
HIGH 8.8
CVE-2024-2353
A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnos…
X6000r Firmware
No fix yet
CRITICAL 9.8
CVE-2024-1783
A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810. Affected is the function logi…
Lr1200gb Firmware
No fix yet
CRITICAL 9.8
CVE-2024-1781EPSS 15%
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg…
X6000r Firmware
No fix yet