Vulnerabilities > Totolink

DATE CVE VULNERABILITY TITLE RISK
2023-10-31 CVE-2023-46978 Missing Authentication for Critical Function vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication.
network
low complexity
totolink CWE-306
7.5
2023-10-31 CVE-2023-46979 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.
network
low complexity
totolink CWE-77
critical
9.8
2023-10-25 CVE-2023-46408 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.652B20230116
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.
network
low complexity
totolink CWE-77
critical
9.8
2023-10-25 CVE-2023-46409 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.652B20230116
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.
network
low complexity
totolink CWE-77
critical
9.8
2023-10-25 CVE-2023-46410 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.652B20230116
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.
network
low complexity
totolink CWE-77
critical
9.8
2023-10-25 CVE-2023-46411 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.652B20230116
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.
network
low complexity
totolink CWE-77
critical
9.8
2023-10-25 CVE-2023-46412 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.652B20230116
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.
network
low complexity
totolink CWE-77
critical
9.8
2023-10-25 CVE-2023-46413 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.652B20230116
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.
network
low complexity
totolink CWE-77
critical
9.8
2023-10-25 CVE-2023-46414 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.652B20230116
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.
network
low complexity
totolink CWE-77
critical
9.8
2023-10-25 CVE-2023-46415 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.652B20230116
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.
network
low complexity
totolink CWE-77
critical
9.8