CVE-2023-36947
- EPSS 1.18%
- Veröffentlicht 16.10.2023 05:15:49
- Zuletzt bearbeitet 21.11.2024 08:10:58
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
CVE-2023-39618
- EPSS 6.03%
- Veröffentlicht 21.08.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 08:15:43
TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.
CVE-2023-39617
- EPSS 6.03%
- Veröffentlicht 21.08.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 08:15:42
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
CVE-2023-31569
- EPSS 4.94%
- Veröffentlicht 06.06.2023 14:15:12
- Zuletzt bearbeitet 08.01.2025 16:15:29
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
CVE-2023-33487
- EPSS 0.94%
- Veröffentlicht 31.05.2023 13:15:09
- Zuletzt bearbeitet 09.01.2025 21:15:23
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.
CVE-2023-33486
- EPSS 0.94%
- Veröffentlicht 31.05.2023 13:15:09
- Zuletzt bearbeitet 09.01.2025 19:15:16
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.
CVE-2023-33485
- EPSS 0.43%
- Veröffentlicht 31.05.2023 13:15:09
- Zuletzt bearbeitet 10.01.2025 16:15:26
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.
CVE-2023-30013
- EPSS 92.09%
- Veröffentlicht 05.05.2023 14:15:09
- Zuletzt bearbeitet 29.01.2025 18:15:45
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
CVE-2022-27003
- EPSS 16.38%
- Veröffentlicht 15.03.2022 22:15:15
- Zuletzt bearbeitet 21.11.2024 06:54:59
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbi...
CVE-2022-27004
- EPSS 30.65%
- Veröffentlicht 15.03.2022 22:15:15
- Zuletzt bearbeitet 21.11.2024 06:54:59
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute a...