Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Total 970 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28497 1 Totolink 2 Cp900, Cp900 Firmware 2023-03-28 N/A 9.8 CRITICAL
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2022-28493 1 Totolink 2 Cp900, Cp900 Firmware 2023-03-27 N/A 9.8 CRITICAL
A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,
CVE-2022-28492 1 Totolink 2 Cp900, Cp900 Firmware 2023-03-27 N/A 9.8 CRITICAL
TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login.
CVE-2022-41526 1 Totolink 2 Nr1800x, Nr1800x Firmware 2022-10-12 N/A 8.8 HIGH
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg function.
CVE-2022-41527 1 Totolink 2 Nr1800x, Nr1800x Firmware 2022-10-12 N/A 8.8 HIGH
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.
CVE-2022-41528 1 Totolink 2 Nr1800x, Nr1800x Firmware 2022-10-12 N/A 8.8 HIGH
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
CVE-2022-41522 1 Totolink 2 Nr1800x, Nr1800x Firmware 2022-10-12 N/A 9.8 CRITICAL
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.
CVE-2022-41524 1 Totolink 2 Nr1800x, Nr1800x Firmware 2022-10-12 N/A 8.8 HIGH
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.
CVE-2022-41523 1 Totolink 2 Nr1800x, Nr1800x Firmware 2022-10-12 N/A 8.8 HIGH
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function.
CVE-2022-41520 1 Totolink 2 Nr1800x, Nr1800x Firmware 2022-10-12 N/A 8.8 HIGH
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
CVE-2022-41521 1 Totolink 2 Nr1800x, Nr1800x Firmware 2022-10-12 N/A 8.8 HIGH
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function.
CVE-2022-41517 1 Totolink 2 Nr1800x, Nr1800x Firmware 2022-10-12 N/A 8.8 HIGH
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function
CVE-2022-38823 1 Totolink 2 T6, T6 Firmware 2022-09-17 N/A 9.8 CRITICAL
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.
CVE-2022-38827 1 Totolink 2 T6, T6 Firmware 2022-09-17 N/A 9.8 CRITICAL
TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi
CVE-2022-40112 1 Totolink 2 A3002r, A3002r Firmware 2022-09-09 N/A 7.5 HIGH
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in binary /bin/boa.
CVE-2022-40109 1 Totolink 2 A3002r, A3002r Firmware 2022-09-09 N/A 9.8 CRITICAL
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.
CVE-2022-40111 1 Totolink 2 A3002r, A3002r Firmware 2022-09-09 N/A 9.8 CRITICAL
In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.
CVE-2022-40110 1 Totolink 2 A3002r, A3002r Firmware 2022-09-08 N/A 7.5 HIGH
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa.
CVE-2022-37842 1 Totolink 2 A860r, A860r Firmware 2022-09-08 N/A 9.8 CRITICAL
In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vulnerability.
CVE-2022-37841 1 Totolink 2 A860r, A860r Firmware 2022-09-08 N/A 7.5 HIGH
In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.