CVE-2023-33486
- EPSS 0.75%
- Veröffentlicht 31.05.2023 13:15:09
- Zuletzt bearbeitet 09.01.2025 19:15:16
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.
CVE-2023-33485
- EPSS 0.34%
- Veröffentlicht 31.05.2023 13:15:09
- Zuletzt bearbeitet 10.01.2025 16:15:26
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.
CVE-2023-30013
- EPSS 90.12%
- Veröffentlicht 05.05.2023 14:15:09
- Zuletzt bearbeitet 29.01.2025 18:15:45
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
CVE-2022-27005
- EPSS 45.94%
- Veröffentlicht 15.03.2022 22:15:15
- Zuletzt bearbeitet 21.11.2024 06:54:59
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbit...
CVE-2022-27004
- EPSS 30.65%
- Veröffentlicht 15.03.2022 22:15:15
- Zuletzt bearbeitet 21.11.2024 06:54:59
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute a...
CVE-2022-27003
- EPSS 30.65%
- Veröffentlicht 15.03.2022 22:15:15
- Zuletzt bearbeitet 21.11.2024 06:54:59
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbi...
CVE-2022-26213
- EPSS 40.63%
- Veröffentlicht 15.03.2022 22:15:14
- Zuletzt bearbeitet 21.11.2024 06:53:36
Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2021-45741
- EPSS 0.53%
- Veröffentlicht 04.02.2022 02:15:08
- Zuletzt bearbeitet 21.11.2024 06:32:59
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.
- EPSS 25.81%
- Veröffentlicht 04.02.2022 02:15:08
- Zuletzt bearbeitet 21.11.2024 06:32:59
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.
CVE-2021-45736
- EPSS 0.41%
- Veröffentlicht 04.02.2022 02:15:08
- Zuletzt bearbeitet 21.11.2024 06:32:58
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.