Filtered by vendor Totolink Subscriptions
Total 976 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-44844 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 6.5 Medium
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44843 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 6.5 Medium
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44842 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 6.5 Medium
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44841 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 6.5 Medium
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the version parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44840 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 6.5 Medium
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the svn parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44839 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 6.5 Medium
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the magicid parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44838 1 Totolink 2 Cp900, Cp900 Firmware 2025-05-22 6.3 Medium
TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44837 1 Totolink 2 Cp900, Cp900 Firmware 2025-05-22 6.3 Medium
TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url or magicid parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44836 1 Totolink 2 Cp900, Cp900 Firmware 2025-05-22 6.3 Medium
TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via the hour or minute parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44848 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-21 6.5 Medium
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44860 1 Totolink 2 Ca300-poe, Ca300-poe Firmware 2025-05-21 6.5 Medium
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44861 1 Totolink 2 Ca300-poe, Ca300-poe Firmware 2025-05-21 6.3 Medium
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44862 1 Totolink 2 Ca300-poe, Ca300-poe Firmware 2025-05-21 6.3 Medium
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44863 1 Totolink 2 Ca300-poe, Ca300-poe Firmware 2025-05-21 6.5 Medium
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2022-40475 1 Totolink 2 A860r, A860r Firmware 2025-05-21 9.8 Critical
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.
CVE-2025-45798 1 Totolink 2 A950rg, A950rg Firmware 2025-05-19 6.5 Medium
A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter.
CVE-2025-45841 1 Totolink 2 Nr1800x, Nr1800x Firmware 2025-05-16 6.5 Medium
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
CVE-2025-45842 1 Totolink 2 Nr1800x, Nr1800x Firmware 2025-05-16 8.8 High
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.
CVE-2025-45843 1 Totolink 2 Nr1800x, Nr1800x Firmware 2025-05-16 8.8 High
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.
CVE-2025-45844 1 Totolink 2 Nr1800x, Nr1800x Firmware 2025-05-16 8.8 High
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.