Totolink

X5000r Firmware

65 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3%
  • Published 15.01.2025 17:15:17
  • Last modified 18.03.2025 15:15:58

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg.

Exploit
  • EPSS 5.86%
  • Published 15.01.2025 17:15:17
  • Last modified 18.03.2025 14:15:41

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.

Exploit
  • EPSS 5.86%
  • Published 15.01.2025 17:15:17
  • Last modified 24.03.2025 16:15:20

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg.

Exploit
  • EPSS 5.86%
  • Published 15.01.2025 17:15:17
  • Last modified 13.03.2025 15:15:50

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg.

Exploit
  • EPSS 5.86%
  • Published 15.01.2025 17:15:17
  • Last modified 18.03.2025 20:15:24

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg.

Exploit
  • EPSS 5.86%
  • Published 15.01.2025 17:15:17
  • Last modified 13.03.2025 15:15:50

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.

Exploit
  • EPSS 5.86%
  • Published 15.01.2025 17:15:17
  • Last modified 18.03.2025 19:15:46

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiScheduleCfg.

Exploit
  • EPSS 5.86%
  • Published 15.01.2025 17:15:17
  • Last modified 20.03.2025 15:15:43

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg.

Exploit
  • EPSS 0.34%
  • Published 13.08.2024 14:15:14
  • Last modified 04.04.2025 14:35:41

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Exploit
  • EPSS 0.71%
  • Published 13.08.2024 14:15:13
  • Last modified 04.04.2025 14:35:31

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.