CVE-2024-32353
- EPSS 2.09%
- Veröffentlicht 14.05.2024 16:17:03
- Zuletzt bearbeitet 04.04.2025 14:27:54
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
CVE-2024-32352
- EPSS 2.18%
- Veröffentlicht 14.05.2024 16:17:03
- Zuletzt bearbeitet 04.04.2025 14:28:01
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.
CVE-2024-32351
- EPSS 2.18%
- Veröffentlicht 14.05.2024 16:17:02
- Zuletzt bearbeitet 04.04.2025 14:28:12
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.
CVE-2024-32350
- EPSS 2.18%
- Veröffentlicht 14.05.2024 16:17:02
- Zuletzt bearbeitet 04.04.2025 14:28:22
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.
- EPSS 0.94%
- Veröffentlicht 14.05.2024 16:17:02
- Zuletzt bearbeitet 04.04.2025 14:28:31
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.
CVE-2024-34921
- EPSS 9.18%
- Veröffentlicht 14.05.2024 15:39:37
- Zuletzt bearbeitet 04.04.2025 14:46:13
TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.
CVE-2024-28640
- EPSS 14.18%
- Veröffentlicht 16.03.2024 06:15:14
- Zuletzt bearbeitet 27.06.2025 14:26:44
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.
CVE-2024-28639
- EPSS 1.24%
- Veröffentlicht 16.03.2024 06:15:14
- Zuletzt bearbeitet 26.03.2025 15:15:49
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.
CVE-2024-25468
- EPSS 0.93%
- Veröffentlicht 17.02.2024 06:15:54
- Zuletzt bearbeitet 28.03.2025 21:15:15
An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.
CVE-2023-6612
- EPSS 30.68%
- Veröffentlicht 08.12.2023 16:15:18
- Zuletzt bearbeitet 21.11.2024 08:44:11
A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDynamicRoute/setFirewallType/setIPSecCfg/setIpPortFilterRules/setLancfg/setLoginPasswordCfg/setMacFilter...