Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-33820 Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt fun… A3002r Firmware No fix yet Fix from $1,9502024-05-01 MEDIUM 6.5 CVE-2024-32334 TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page. N300rt Firmware No fix yet Fix from $1,6002024-04-18 MEDIUM 5.4 CVE-2024-32335 TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page. N300rt Firmware No fix yet Fix from $1,6002024-04-18 MEDIUM 6.8 CVE-2024-32326 TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig func… Ex200 Firmware No fix yet Fix from $1,6002024-04-18 MEDIUM 6.1 CVE-2024-32332 TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page. N300rt Firmware No fix yet Fix from $1,6002024-04-18 MEDIUM 5.5 CVE-2024-32327 TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page. N300rt Firmware No fix yet Fix from $1,6002024-04-18 MEDIUM 5.9 CVE-2024-28402 TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page. X2000r Firmware 1.0.0-b20231213.1013+ Fix from $1,6002024-04-11 HIGH 7.5 CVE-2024-31817EPSS 55% In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg. Ex200 Firmware No fix yet Fix from $1,9502024-04-08 CRITICAL 9.8 CVE-2024-31807 TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSync… Ex200 Firmware No fix yet Fix from $2,3002024-04-08 CRITICAL 9.1 CVE-2024-31815 In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh Ex200 Firmware No fix yet Fix from $2,3002024-04-08 HIGH 8.8 CVE-2024-31808 TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWe… Ex200 Firmware No fix yet Fix from $1,9502024-04-08 HIGH 8.8 CVE-2024-31809 TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgr… Ex200 Firmware No fix yet Fix from $1,9502024-04-08 HIGH 8.8 CVE-2024-31814EPSS 9% TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function. Ex200 Firmware No fix yet Fix from $1,9502024-04-08 HIGH 8.4 CVE-2024-31813 TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default. Ex200 Firmware Mitigation only Fix from $1,9502024-04-08 HIGH 8.0 CVE-2024-31811 TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLang… Ex200 Firmware No fix yet Fix from $1,9502024-04-08 HIGH 7.5 CVE-2024-31816 In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg. Ex200 Firmware Mitigation only Fix from $1,9502024-04-08 MEDIUM 6.5 CVE-2024-31805 TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setT… Ex200 Firmware No fix yet Fix from $1,6002024-04-08 MEDIUM 6.5 CVE-2024-31806 TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot… Ex200 Firmware Mitigation only Fix from $1,6002024-04-08 MEDIUM 6.5 CVE-2024-31812 In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConf… Ex200 Firmware Mitigation only Fix from $1,6002024-04-08 HIGH 8.0 CVE-2024-27521 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parame… A3300r Firmware Mitigation only Fix from $1,9502024-03-26 MEDIUM 5.4 CVE-2024-29419 There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.101… X2000r Firmware 1.0.0-b20231213.1013+ Fix from $1,6002024-03-20 CRITICAL 9.8 CVE-2024-28639 Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrar… X5000r Firmware No fix yet Fix from $2,3002024-03-16 HIGH 7.5 CVE-2024-28640EPSS 14% Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial … X5000r Firmware Mitigation only Fix from $1,9502024-03-16 HIGH 8.0 CVE-2024-28404 TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page. X2000r Firmware 1.0.0-b20231213.1013+ Fix from $1,9502024-03-15 MEDIUM 5.4 CVE-2024-28401 TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page. X2000r Firmware 1.0.0-b20231213.1013+ Fix from $1,6002024-03-15 MEDIUM 5.4 CVE-2024-28403 TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page. X2000r Firmware 1.0.0-b20231213.1013+ Fix from $1,6002024-03-15 HIGH 8.0 CVE-2024-28338 A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie. A8000ru Firmware No fix yet Fix from $1,9502024-03-12 HIGH 8.8 CVE-2024-2353 A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnos… X6000r Firmware No fix yet Fix from $1,9502024-03-10 CRITICAL 9.8 CVE-2024-1783 A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810. Affected is the function logi… Lr1200gb Firmware No fix yet Fix from $2,3002024-02-23 CRITICAL 9.8 CVE-2024-1781EPSS 15% A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg… X6000r Firmware No fix yet Fix from $2,3002024-02-23