Loading HuntDB...

Vulnerabilities

CVE-2023-46557

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAPVLAN.

Published Oct 25, 2023

CVE-2023-46551

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formReflashClientTbl.

Published Oct 25, 2023

CVE-2023-46424

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function.

Published Oct 25, 2023

CVE-2023-46408

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.

Published Oct 25, 2023

CVE-2023-46547

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSysLog.

Published Oct 25, 2023

CVE-2023-46545

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWsc.

Published Oct 25, 2023

CVE-2023-46553

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formParentControl.

Published Oct 25, 2023

CVE-2023-46550

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.

Published Oct 25, 2023

CVE-2023-46413

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.

Published Oct 25, 2023

CVE-2023-46414

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.

Published Oct 25, 2023

CVE-2023-46554

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDel.

Published Oct 25, 2023

CVE-2023-46418

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.

Published Oct 25, 2023

CVE-2023-46422

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.

Published Oct 25, 2023

CVE-2023-46543

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlSiteSurvey.

Published Oct 25, 2023

CVE-2023-46540

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formNtp.

Published Oct 25, 2023

CVE-2023-46421

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.

Published Oct 25, 2023

CVE-2023-46416

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.

Published Oct 25, 2023

CVE-2023-46555

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPortFw.

Published Oct 25, 2023

CVE-2023-46560

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.

Published Oct 25, 2023

CVE-2023-46546

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formStats.

Published Oct 25, 2023

CVE-2023-46412

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.

Published Oct 25, 2023

CVE-2023-46417

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.

Published Oct 25, 2023

CVE-2023-46544

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWirelessTbl.

Published Oct 25, 2023

CVE-2023-46423

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function.

Published Oct 25, 2023

CVE-2023-46563

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.

Published Oct 25, 2023

CVE-2023-46542

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMeshUploadConfig.

Published Oct 25, 2023

CVE-2023-46564

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.

Published Oct 25, 2023

CVE-2023-46549

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSetLg.

Published Oct 25, 2023

CVE-2023-46558

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.

Published Oct 25, 2023

CVE-2023-46541

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpv6Setup.

Published Oct 25, 2023

CVE-2023-46548

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlanRedirect.

Published Oct 25, 2023

CVE-2023-46410

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.

Published Oct 25, 2023

CVE-2023-46420

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.

Published Oct 25, 2023

CVE-2023-46562

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.

Published Oct 25, 2023

CVE-2023-46559

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.

Published Oct 25, 2023

CVE-2023-46552

UNKNOWN

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAP.

Published Oct 25, 2023

CVE-2023-46409

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.

Published Oct 25, 2023

CVE-2023-46419

UNKNOWN

TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.

Published Oct 25, 2023

CVE-2023-46574

UNKNOWN

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

Published Oct 24, 2023

CVE-2023-45984

UNKNOWN

TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.

Published Oct 16, 2023

CVE-2023-36955

UNKNOWN

TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.

Published Oct 16, 2023

CVE-2023-36953

UNKNOWN

TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.

Published Oct 16, 2023

CVE-2023-36340

UNKNOWN

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

Published Oct 16, 2023

CVE-2023-36950

UNKNOWN

TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

Published Oct 16, 2023

CVE-2023-36947

UNKNOWN

TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.

Published Oct 16, 2023

CVE-2023-36954

UNKNOWN

TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.

Published Oct 16, 2023

CVE-2023-36952

UNKNOWN

TOTOLINK CP300+ V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the pingIp parameter in the function setDiagnosisCfg.

Published Oct 16, 2023

CVE-2023-43141

UNKNOWN

TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.

Published Sep 25, 2023

CVE-2023-4746

HIGH

A vulnerability classified as critical has been found in TOTOLINK N200RE V5 9.3.5u.6437_B20230519. This affects the function Validity_check. The manipulation leads to format string. It is possible to initiate the attack remotely. The root-cause of the vulnerability is a format string issue. But the impact is to bypass the validation which leads to to OS command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238635.

Published Sep 04, 2023

CVE-2023-39618

UNKNOWN

TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.

Published Aug 21, 2023