CVE-2024-29419
- EPSS 0.1%
- Published 20.03.2024 15:15:07
- Last modified 27.03.2025 21:15:47
There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.
- EPSS 0.05%
- Published 15.03.2024 17:15:08
- Last modified 08.04.2025 15:23:01
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.
CVE-2024-28401
- EPSS 0.1%
- Published 15.03.2024 17:15:08
- Last modified 28.03.2025 19:15:21
TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.
CVE-2024-28403
- EPSS 0.1%
- Published 15.03.2024 16:15:08
- Last modified 27.03.2025 20:15:25
TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.
CVE-2024-22529
- EPSS 2.74%
- Published 25.01.2024 16:15:08
- Last modified 04.06.2025 22:15:24
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.
CVE-2024-0579
- EPSS 1.02%
- Published 16.01.2024 17:15:08
- Last modified 03.06.2025 09:15:21
A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads to command i...
CVE-2023-7222
- EPSS 0.19%
- Published 09.01.2024 16:15:43
- Last modified 21.11.2024 08:45:32
A vulnerability was found in Totolink X2000R 1.0.0-B20221212.1452. It has been declared as critical. This vulnerability affects the function formTmultiAP of the file /bin/boa of the component HTTP POST Request Handler. The manipulation of the argumen...
CVE-2023-7208
- EPSS 0.51%
- Published 07.01.2024 07:15:07
- Last modified 21.11.2024 08:45:30
A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects the function formTmultiAP of the file /bin/boa. The manipulation leads to buffer overflow. VDB-249742 is the identifier assigned ...
CVE-2023-51136
- EPSS 0.29%
- Published 30.12.2023 16:15:44
- Last modified 21.11.2024 08:37:52
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSchedule.
CVE-2023-51135
- EPSS 0.29%
- Published 30.12.2023 16:15:44
- Last modified 21.11.2024 08:37:52
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPasswordSetup.