Skip to main content

Vendor archive

totolink CVEs

Beta · best-effort

1,107 CVEs tagged to vendor totolink429 Critical, 429 High, 198 Medium, 51 Low, 0 Unrated.

CVE-2025-60336

Published Oct 22, 2025

A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

CVSS 7.5 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-60335

Published Oct 22, 2025

A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

CVSS 7.5 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-60334

Published Oct 22, 2025

TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to…

CVSS 7.5 · High
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-60333

Published Oct 22, 2025

TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attacke…

CVSS 7.5 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-11444

Published Oct 8, 2025

A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the com…

CVSS 7.4 · High
evidence mentions
6
Buzz score
35.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-61045

Published Oct 1, 2025

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-61044

Published Oct 1, 2025

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-11005

Published Sep 25, 2025

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R:…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-57623

Published Sep 25, 2025

A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-52907

Published Sep 24, 2025

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

CVSS 7.3 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-52906

Published Sep 24, 2025

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R:…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-52053

Published Sep 15, 2025

TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows un…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
25.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-57579

Published Sep 12, 2025

An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password

CVSS 8.0 · High
evidence mentions
2
Buzz score
25.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-9577

Published Aug 28, 2025

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Inte…

CVSS 1.1 · Low
evidence mentions
6
Buzz score
35.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-9533

Published Aug 27, 2025

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode wi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55591

Published Aug 18, 2025

TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 101-125 of 1,107 CVEsPage 5 of 45