Vulnerabilities
Vulnerable Software
Totolink:  Security Vulnerabilities
TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-10-16
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-10-16
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
CVSS Score
9.8
EPSS Score
0.015
Published
2023-10-16
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
CVSS Score
9.8
EPSS Score
0.016
Published
2023-10-16
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-10-16
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-10-16
TOTOLINK CP300+ V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the pingIp parameter in the function setDiagnosisCfg.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-10-16
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-09-25
A vulnerability classified as critical has been found in TOTOLINK N200RE V5 9.3.5u.6437_B20230519. This affects the function Validity_check. The manipulation leads to format string. It is possible to initiate the attack remotely. The root-cause of the vulnerability is a format string issue. But the impact is to bypass the validation which leads to to OS command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238635.
CVSS Score
8.8
EPSS Score
0.032
Published
2023-09-04
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
CVSS Score
9.8
EPSS Score
0.017
Published
2023-08-21


Contact Us

Shodan ® - All rights reserved