Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-51021 TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg in… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51022 TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg … Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51033 TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface. Ex1200l Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51034 TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface. Ex1200l Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51035 TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface. Ex1200l Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-50147 There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its… A3700r Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51023 TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘host_time’ parameter of the NTPSyncWithHost interface o… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51024 TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘tz’ parameter of the setNtpCfg interface o… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51025 TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCf… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51026 TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg in… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51027 TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘apcliAuthMode’ parameter of the setWiFiExt… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51028 TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtende… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-6906 A vulnerability, which was classified as critical, was found in Totolink A7100RU 7.4cu.2313_B20191024. Affected is the function main of the file /cgi… A7100ru Firmware No fix yet Fix from $2,3002023-12-18 CRITICAL 9.8 CVE-2023-49417 TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg. A7000r Firmware No fix yet Fix from $2,3002023-12-11 CRITICAL 9.8 CVE-2023-49418 TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules. A7000r Firmware No fix yet Fix from $2,3002023-12-11 CRITICAL 9.8 CVE-2023-6612EPSS 31% A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDyn… X5000r Firmware No fix yet Fix from $2,3002023-12-08 CRITICAL 9.8 CVE-2023-48860 TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end sec… N300rt Firmware No fix yet Fix from $2,3002023-12-07 HIGH 8.8 CVE-2023-48859 TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end sec… A3002ru Firmware No fix yet Fix from $1,9502023-12-06 CRITICAL 9.8 CVE-2023-48799 TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution. X6000r Firmware No fix yet Fix from $2,3002023-12-04 CRITICAL 9.8 CVE-2023-48800 In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the … X6000r Firmware No fix yet Fix from $2,3002023-12-04 CRITICAL 9.8 CVE-2023-48801 In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the … X6000r Firmware No fix yet Fix from $2,3002023-12-01 CRITICAL 9.8 CVE-2023-43453 An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter… X6000r Firmware No fix yet Fix from $2,3002023-12-01 CRITICAL 9.8 CVE-2023-43454 An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName par… X6000r Firmware No fix yet Fix from $2,3002023-12-01 CRITICAL 9.8 CVE-2023-43455 An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command para… X6000r Firmware No fix yet Fix from $2,3002023-12-01 CRITICAL 9.8 CVE-2023-48808 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48810 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48811 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48812 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function t… X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48802 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-48803 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function … X6000r Firmware No fix yet Fix from $2,3002023-11-30