Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2020-23617
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scri…
N200re Firmware
Mitigation only
HIGH 7.5
CVE-2021-43663
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.
Ex300 V2 Firmware
No fix yet
MEDIUM 6.5
CVE-2021-43662
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.
Ex300 V2 Firmware
No fix yet
MEDIUM 6.1
CVE-2021-43661
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.
Ex300 V2 Firmware
No fix yet
HIGH 8.8
CVE-2022-25008
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
Ex300 V2 Firmware
No fix yet
CRITICAL 9.8
CVE-2021-46007
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not…
Ar3100r Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-46009EPSS 13%
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set…
A3100r Firmware
Mitigation only
HIGH 8.8
CVE-2021-46008
In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to th…
A3100r Firmware
Mitigation only
HIGH 8.8
CVE-2021-46010
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can…
A3100r Firmware
Mitigation only
HIGH 8.1
CVE-2021-43664
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.
Ex300 V2 Firmware
No fix yet
MEDIUM 6.5
CVE-2021-46006EPSS 5%
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure m…
A3100r Firmware
No fix yet
CRITICAL 9.8
CVE-2021-43636
Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function when processing host data in…
T10 V2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-26186
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.
N600r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26187EPSS 20%
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.
N600r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26188
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.
N600r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26189
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.
N600r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-27003
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in th…
X5000r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-27004
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in th…
X5000r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-27005EPSS 5%
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in th…
X5000r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26206
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26207
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26208
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26209
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26210EPSS 6%
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26211
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26212
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26213EPSS 26%
Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz par…
X5000r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26214
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…
A830r Firmware
No fix yet
CRITICAL 9.8
CVE-2021-44620
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
A3100r Firmware
after 4.1.2cu.5050_b20200504
CRITICAL 9.8
CVE-2022-25075EPSS 54%
TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows a…
A3000ru Firmware
Patch available