Lucene search

K

TOTOLINK Security Vulnerabilities

cve
cve

CVE-2022-29646

An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtain sensitive information via a crafted web request.

5.3CVSS

4.9AI Score

0.001EPSS

2022-05-18 12:15 PM
42
2
cve
cve

CVE-2022-32044

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80.

7.5CVSS

7.8AI Score

0.001EPSS

2022-07-01 06:15 PM
50
7
cve
cve

CVE-2022-32045

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.

7.5CVSS

7.7AI Score

0.001EPSS

2022-07-01 06:15 PM
41
5
cve
cve

CVE-2022-32046

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.

7.5CVSS

7.7AI Score

0.001EPSS

2022-07-01 06:15 PM
53
5
cve
cve

CVE-2022-32047

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4.

7.5CVSS

7.7AI Score

0.001EPSS

2022-07-01 06:15 PM
37
5
cve
cve

CVE-2022-32048

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88.

7.5CVSS

7.8AI Score

0.001EPSS

2022-07-01 06:15 PM
53
6
cve
cve

CVE-2022-32049

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540.

7.5CVSS

7.7AI Score

0.001EPSS

2022-07-01 06:15 PM
57
8
cve
cve

CVE-2022-32050

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.

7.5CVSS

7.7AI Score

0.001EPSS

2022-07-01 06:15 PM
44
6
cve
cve

CVE-2022-32051

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN_004133c4.

7.5CVSS

7.7AI Score

0.001EPSS

2022-07-01 06:15 PM
54
7
cve
cve

CVE-2022-32052

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4.

7.5CVSS

7.7AI Score

0.001EPSS

2022-07-01 06:15 PM
54
6
cve
cve

CVE-2022-32053

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.

7.5CVSS

7.7AI Score

0.001EPSS

2022-07-01 06:15 PM
43
6
cve
cve

CVE-2022-32449

TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet.

9.8CVSS

9.6AI Score

0.178EPSS

2022-07-07 07:15 PM
48
7
cve
cve

CVE-2022-32993

TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.

9.8CVSS

9.5AI Score

0.007EPSS

2022-08-29 09:15 PM
27
5
cve
cve

CVE-2022-34993

Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.

9.8CVSS

9.6AI Score

0.018EPSS

2022-08-04 07:15 PM
43
5
cve
cve

CVE-2022-35491

TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.

9.8CVSS

9.4AI Score

0.01EPSS

2022-08-10 08:15 PM
35
4
cve
cve

CVE-2022-36455

TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 03:15 PM
35
5
cve
cve

CVE-2022-36456

TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
27
6
cve
cve

CVE-2022-36458

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
37
4
cve
cve

CVE-2022-36459

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
33
4
cve
cve

CVE-2022-36460

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
33
4
cve
cve

CVE-2022-36461

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
32
4
cve
cve

CVE-2022-36462

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
33
2
cve
cve

CVE-2022-36463

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
20
2
cve
cve

CVE-2022-36464

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
30
2
cve
cve

CVE-2022-36465

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
31
6
cve
cve

CVE-2022-36466

TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
32
4
cve
cve

CVE-2022-36479

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
31
2
cve
cve

CVE-2022-36480

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
31
2
cve
cve

CVE-2022-36481

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
29
4
cve
cve

CVE-2022-36482

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the lang parameter in the function setLanguageCfg.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
31
4
cve
cve

CVE-2022-36483

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the pppoeUser parameter.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
36
4
cve
cve

CVE-2022-36484

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the function setDiagnosisCfg.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
37
4
cve
cve

CVE-2022-36485

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
29
4
cve
cve

CVE-2022-36486

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
29
4
cve
cve

CVE-2022-36487

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
35
4
cve
cve

CVE-2022-36488

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
28
4
cve
cve

CVE-2022-36610

TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

7.8CVSS

7.7AI Score

0.001EPSS

2022-08-29 12:15 AM
26
6
cve
cve

CVE-2022-36611

TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

7.8CVSS

7.7AI Score

0.001EPSS

2022-08-29 12:15 AM
39
9
cve
cve

CVE-2022-36612

TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

7.8CVSS

7.7AI Score

0.001EPSS

2022-08-29 12:15 AM
44
10
cve
cve

CVE-2022-36613

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

7.8CVSS

7.7AI Score

0.001EPSS

2022-08-29 12:15 AM
41
10
cve
cve

CVE-2022-36614

TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

7.8CVSS

7.7AI Score

0.001EPSS

2022-08-29 12:15 AM
43
9
cve
cve

CVE-2022-36615

TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

7.8CVSS

7.7AI Score

0.001EPSS

2022-08-29 12:15 AM
25
5
cve
cve

CVE-2022-36616

TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

7.8CVSS

7.7AI Score

0.001EPSS

2022-08-29 12:15 AM
38
5
cve
cve

CVE-2022-37075

TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 02:15 PM
26
4
cve
cve

CVE-2022-37076

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 02:15 PM
30
4
cve
cve

CVE-2022-37077

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser parameter.

7.8CVSS

7.8AI Score

0.0005EPSS

2022-08-25 03:15 PM
28
5
cve
cve

CVE-2022-37078

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at /setting/setLanguageCfg.

7.8CVSS

7.9AI Score

0.002EPSS

2022-08-25 03:15 PM
39
4
cve
cve

CVE-2022-37079

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 03:15 PM
33
6
cve
cve

CVE-2022-37080

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command parameter at setting/setTracerouteCfg.

7.8CVSS

7.9AI Score

0.0005EPSS

2022-08-25 03:15 PM
30
6
cve
cve

CVE-2022-37081

TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.

7.8CVSS

7.8AI Score

0.002EPSS

2022-08-25 03:15 PM
29
6
Total number of security vulnerabilities598