Vulnerabilities > Totolink > N150Rt Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2025-04-28 CVE-2025-3993 Classic Buffer Overflow vulnerability in Totolink N150Rt Firmware 3.4.0B20190525
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical.
network
low complexity
totolink CWE-120
8.8
2025-04-28 CVE-2025-3991 Classic Buffer Overflow vulnerability in Totolink N150Rt Firmware 3.4.0B20190525
A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525.
network
low complexity
totolink CWE-120
8.8
2025-04-28 CVE-2025-3992 Classic Buffer Overflow vulnerability in Totolink N150Rt Firmware 3.4.0B20190525
A vulnerability has been found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical.
network
low complexity
totolink CWE-120
8.8
2025-04-27 CVE-2025-3989 Classic Buffer Overflow vulnerability in Totolink N150Rt Firmware 3.4.0B20190525
A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525.
network
low complexity
totolink CWE-120
8.8
2025-04-27 CVE-2025-3990 Classic Buffer Overflow vulnerability in Totolink N150Rt Firmware 3.4.0B20190525
A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525.
network
low complexity
totolink CWE-120
8.8
2025-04-27 CVE-2025-3987 Injection vulnerability in Totolink N150Rt Firmware 3.4.0B20190525
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525.
network
low complexity
totolink CWE-74
8.8
2025-04-27 CVE-2025-3988 Classic Buffer Overflow vulnerability in Totolink N150Rt Firmware 3.4.0B20190525
A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525.
network
low complexity
totolink CWE-120
8.8
2020-12-09 CVE-2020-25499 Missing Authorization vulnerability in Totolink products
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'.
network
low complexity
totolink CWE-862
8.8
2020-01-27 CVE-2019-19824 OS Command Injection vulnerability in Totolink products
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available.
network
low complexity
totolink CWE-78
8.8
2020-01-27 CVE-2019-19823 Insufficiently Protected Credentials vulnerability in multiple products
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file.
7.5