Vulnerabilities > Totolink > X6000R Firmware

DATE CVE VULNERABILITY TITLE RISK
2024-11-22 CVE-2024-52723 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.1041B20240224
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering.
network
low complexity
totolink CWE-78
critical
9.8
2024-08-18 CVE-2024-7907 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719.
network
low complexity
totolink CWE-77
critical
9.8
2024-03-10 CVE-2024-2353 Unspecified vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719.
network
low complexity
totolink
8.8
2024-02-20 CVE-2024-1661 Unspecified vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719.
local
low complexity
totolink
5.5
2024-01-24 CVE-2023-52038 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.
network
low complexity
totolink CWE-77
critical
9.8
2024-01-24 CVE-2023-52039 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.
network
low complexity
totolink CWE-77
critical
9.8
2024-01-24 CVE-2023-52040 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
network
low complexity
totolink CWE-77
critical
9.8
2024-01-16 CVE-2023-52042 Unspecified vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.
network
low complexity
totolink
critical
9.8
2024-01-16 CVE-2023-52041 Unspecified vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program.
network
low complexity
totolink
critical
9.8
2023-12-30 CVE-2023-50651 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
network
low complexity
totolink CWE-78
critical
9.8