Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Total 514 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-46412 1 Totolink 2 X6000r, X6000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.
CVE-2023-46563 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.
CVE-2023-36954 1 Totolink 2 Cp300\+, Cp300\+ Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
CVE-2023-40041 1 Totolink 2 T10 V2, T10 V2 Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code.
CVE-2023-46545 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWsc.
CVE-2023-46554 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDel.
CVE-2023-36955 1 Totolink 2 Cp300\+, Cp300\+ Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
CVE-2023-46409 1 Totolink 2 X6000r, X6000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.
CVE-2023-36953 1 Totolink 2 Cp300\+, Cp300\+ Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
CVE-2023-46552 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAP.
CVE-2023-46547 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSysLog.
CVE-2023-46564 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.
CVE-2023-46546 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formStats.
CVE-2023-46411 1 Totolink 2 X6000r, X6000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.
CVE-2023-46415 1 Totolink 2 X6000r, X6000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.
CVE-2023-46555 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPortFw.
CVE-2023-46559 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.
CVE-2023-46549 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSetLg.
CVE-2023-46542 1 Totolink 2 X2000r, X2000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMeshUploadConfig.
CVE-2023-46414 1 Totolink 2 X6000r, X6000r Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.