Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Filtered by product Ex1200t
Total 15 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42875 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-02-14 10.0 HIGH 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
CVE-2021-42877 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-02-14 7.8 HIGH 7.5 HIGH
TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.
CVE-2021-42872 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-02-14 10.0 HIGH 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.
CVE-2023-52032 1 Totolink 2 Ex1200t, Ex1200t Firmware 2024-01-17 N/A 9.8 CRITICAL
TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.
CVE-2021-42887 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 7.5 HIGH 9.8 CRITICAL
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
CVE-2021-42885 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 7.5 HIGH 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can control deviceName to attack.
CVE-2021-42889 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 5.0 MEDIUM 7.5 HIGH
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.
CVE-2021-42886 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 5.0 MEDIUM 7.5 HIGH
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file.
CVE-2021-42890 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 7.5 HIGH 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.
CVE-2021-42893 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 5.0 MEDIUM 7.5 HIGH
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.
CVE-2022-25008 1 Totolink 4 Ex1200t, Ex1200t Firmware, Ex300 V2 and 1 more 2023-12-10 5.8 MEDIUM 8.8 HIGH
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
CVE-2021-42891 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 5.0 MEDIUM 7.5 HIGH
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
CVE-2021-42892 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 5.0 MEDIUM 4.3 MEDIUM
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.
CVE-2021-42884 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 7.5 HIGH 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control thedeviceName to attack.
CVE-2021-42888 1 Totolink 2 Ex1200t, Ex1200t Firmware 2023-12-10 7.5 HIGH 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack.