Vulnerabilities
Vulnerable Software
Totolink:  Security Vulnerabilities
A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-229374 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
2.3
EPSS Score
0.003
Published
2023-05-18
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
CVSS Score
9.8
EPSS Score
0.014
Published
2023-05-18
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
CVSS Score
9.8
EPSS Score
0.029
Published
2023-05-16
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
CVSS Score
9.8
EPSS Score
0.021
Published
2023-05-05
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.
CVSS Score
9.8
EPSS Score
0.021
Published
2023-05-05
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
CVSS Score
9.8
EPSS Score
0.259
Published
2023-05-05
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
CVSS Score
9.8
EPSS Score
0.02
Published
2023-04-14
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function.
CVSS Score
9.8
EPSS Score
0.02
Published
2023-04-14
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
CVSS Score
9.8
EPSS Score
0.02
Published
2023-04-14
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.
CVSS Score
9.8
EPSS Score
0.021
Published
2023-04-14


Contact Us

Shodan ® - All rights reserved