Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Total 515 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-46976 1 Totolink 2 A3300r, A3300r Firmware 2023-11-08 N/A 9.8 CRITICAL
TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.
CVE-2023-46977 1 Totolink 2 Lr1200gb, Lr1200gb Firmware 2023-11-08 N/A 9.8 CRITICAL
TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.
CVE-2023-46978 1 Totolink 2 X6000r, X6000r Firmware 2023-11-08 N/A 7.5 HIGH
TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication.
CVE-2023-46979 1 Totolink 2 X6000r, X6000r Firmware 2023-11-08 N/A 9.8 CRITICAL
TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.
CVE-2023-31569 1 Totolink 2 X5000r, X5000r Firmware 2023-11-07 N/A 9.8 CRITICAL
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
CVE-2023-46542 1 Totolink 2 X2000r, X2000r Firmware 2023-11-02 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMeshUploadConfig.
CVE-2023-46541 1 Totolink 2 X2000r, X2000r Firmware 2023-11-02 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpv6Setup.
CVE-2023-46543 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlSiteSurvey.
CVE-2023-46544 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWirelessTbl.
CVE-2023-46540 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formNtp.
CVE-2023-46548 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlanRedirect.
CVE-2023-46549 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSetLg.
CVE-2023-46550 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.
CVE-2023-46551 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formReflashClientTbl.
CVE-2023-46552 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAP.
CVE-2023-46553 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formParentControl.
CVE-2023-46545 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWsc.
CVE-2023-46546 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formStats.
CVE-2023-46547 1 Totolink 2 X2000r, X2000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSysLog.
CVE-2023-46424 1 Totolink 2 X6000r, X6000r Firmware 2023-11-01 N/A 9.8 CRITICAL
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function.