Vulnerabilities
Vulnerable Software
Totolink:  Security Vulnerabilities
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.
CVSS Score
9.8
EPSS Score
0.019
Published
2023-02-03
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function.
CVSS Score
9.8
EPSS Score
0.019
Published
2023-02-03
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function.
CVSS Score
9.8
EPSS Score
0.019
Published
2023-02-03
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.
CVSS Score
9.8
EPSS Score
0.019
Published
2023-02-03
A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.
CVSS Score
9.8
EPSS Score
0.009
Published
2023-02-02
An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.
CVSS Score
9.8
EPSS Score
0.024
Published
2023-01-27
An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to obtain the root password via a brute-force attack.
CVSS Score
5.5
EPSS Score
0.002
Published
2023-01-27
Totolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter.
CVSS Score
7.5
EPSS Score
0.014
Published
2023-01-27
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the setting/setOpenVpnCertGenerationCfg function.
CVSS Score
9.8
EPSS Score
0.02
Published
2023-01-20
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the setting/setOpenVpnCertGenerationCfg function.
CVSS Score
9.8
EPSS Score
0.02
Published
2023-01-20


Contact Us

Shodan ® - All rights reserved