Skip to main content

Vendor archive

totolink CVEs

Beta · best-effort

1,107 CVEs tagged to vendor totolink429 Critical, 429 High, 198 Medium, 51 Low, 0 Unrated.

CVE-2025-60685

Published Nov 13, 2025

A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file u…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60683

Published Nov 13, 2025

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handl…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60682

Published Nov 13, 2025

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-63154

Published Nov 10, 2025

TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urldecode function. This vulnerability allows attackers to caus…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63153

Published Nov 10, 2025

TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode function. This vulnerability allows attackers to cause a D…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63459

Published Oct 31, 2025

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63465

Published Oct 31, 2025

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63464

Published Oct 31, 2025

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63463

Published Oct 31, 2025

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63462

Published Oct 31, 2025

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to caus…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63461

Published Oct 31, 2025

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63460

Published Oct 31, 2025

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63469

Published Oct 31, 2025

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63468

Published Oct 31, 2025

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63467

Published Oct 31, 2025

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63466

Published Oct 31, 2025

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to caus…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-12260

Published Oct 27, 2025

A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component POST…

CVSS 7.4 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12259

Published Oct 27, 2025

A flaw has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component POST Paramet…

CVSS 7.4 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12258

Published Oct 27, 2025

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. Impacted is the function setOpModeCfg of the file /cgi-bin/cstecgi.cg of the component POST Parameter Handl…

CVSS 8.7 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12241

Published Oct 27, 2025

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This impacts the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Parameter H…

CVSS 7.4 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12240

Published Oct 27, 2025

A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the…

CVSS 7.4 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12239

Published Oct 27, 2025

A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Executing manipulation…

CVSS 7.4 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 76-100 of 1,107 CVEsPage 4 of 45