Filtered by vendor Totolink Subscriptions
Total 640 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-46631 1 Totolink 2 A7100ru, A7100ru Firmware 2024-08-03 9.8 Critical
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.
CVE-2022-44843 1 Totolink 2 A7100ru, A7100ru Firmware 2024-08-03 9.8 Critical
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.
CVE-2022-44844 1 Totolink 2 A7100ru, A7100ru Firmware 2024-08-03 9.8 Critical
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.
CVE-2022-44254 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 8.8 High
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.
CVE-2022-44250 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 9.8 Critical
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.
CVE-2022-44256 1 Totolink 2 Nr1800x, Nr1800x Firmware 2024-08-03 8.8 High
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.
CVE-2022-44258 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 8.8 High
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.
CVE-2022-44249 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 9.8 Critical
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.
CVE-2022-44253 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 8.8 High
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.
CVE-2022-44251 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 9.8 Critical
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
CVE-2022-44257 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 8.8 High
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.
CVE-2022-44252 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 9.8 Critical
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
CVE-2022-44260 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 8.8 High
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.
CVE-2022-44259 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 8.8 High
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.
CVE-2022-44255 1 Totolink 2 Lr350, Lr350 Firmware 2024-08-03 9.8 Critical
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.
CVE-2022-41520 1 Totolink 2 Nr1800x, Nr1800x Firmware 2024-08-03 8.8 High
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
CVE-2022-41525 1 Totolink 2 Nr1800x, Nr1800x Firmware 2024-08-03 9.8 Critical
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.
CVE-2022-41517 1 Totolink 2 Nr1800x, Nr1800x Firmware 2024-08-03 8.8 High
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function
CVE-2022-41522 1 Totolink 2 Nr1800x, Nr1800x Firmware 2024-08-03 9.8 Critical
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.
CVE-2022-41523 1 Totolink 2 Nr1800x, Nr1800x Firmware 2024-08-03 8.8 High
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function.