Vulnerabilities > Totolink > X5000R Firmware

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2024-42747 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6369B20230113
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg.
network
low complexity
totolink CWE-78
8.8
2024-08-12 CVE-2024-42748 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6369B20230113
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg.
network
low complexity
totolink CWE-78
8.8
2024-03-16 CVE-2024-28639 Classic Buffer Overflow vulnerability in Totolink A7000R Firmware and X5000R Firmware
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.
network
low complexity
totolink CWE-120
critical
9.8
2024-02-17 CVE-2024-25468 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6369B20230113
An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.
network
low complexity
totolink CWE-78
7.5
2023-12-08 CVE-2023-6612 Unspecified vulnerability in Totolink X5000R Firmware 9.1.0Cu.2300B20230112
A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112.
network
low complexity
totolink
critical
9.8
2023-10-16 CVE-2023-45984 Out-of-bounds Write vulnerability in Totolink A7000R Firmware and X5000R Firmware
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.
network
low complexity
totolink CWE-787
critical
9.8
2023-10-16 CVE-2023-45985 Out-of-bounds Write vulnerability in Totolink A7000R Firmware and X5000R Firmware
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules.
network
low complexity
totolink CWE-787
7.5
2023-10-16 CVE-2023-36950 Out-of-bounds Write vulnerability in Totolink A7000R Firmware and X5000R Firmware
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
network
low complexity
totolink CWE-787
critical
9.8
2023-10-16 CVE-2023-36947 Out-of-bounds Write vulnerability in Totolink A7000R Firmware and X5000R Firmware
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
network
low complexity
totolink CWE-787
critical
9.8
2023-08-21 CVE-2023-39617 Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2089B20211224/9.1.0Cu.2350B20230313
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
network
low complexity
totolink CWE-77
critical
9.8