Totolink

X5000r Firmware

65 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.75%
  • Veröffentlicht 31.05.2023 13:15:09
  • Zuletzt bearbeitet 09.01.2025 19:15:16

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 31.05.2023 13:15:09
  • Zuletzt bearbeitet 10.01.2025 16:15:26

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.

Exploit
  • EPSS 90.12%
  • Veröffentlicht 05.05.2023 14:15:09
  • Zuletzt bearbeitet 29.01.2025 18:15:45

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.

Exploit
  • EPSS 45.94%
  • Veröffentlicht 15.03.2022 22:15:15
  • Zuletzt bearbeitet 21.11.2024 06:54:59

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbit...

Exploit
  • EPSS 30.65%
  • Veröffentlicht 15.03.2022 22:15:15
  • Zuletzt bearbeitet 21.11.2024 06:54:59

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute a...

Exploit
  • EPSS 30.65%
  • Veröffentlicht 15.03.2022 22:15:15
  • Zuletzt bearbeitet 21.11.2024 06:54:59

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbi...

Exploit
  • EPSS 40.63%
  • Veröffentlicht 15.03.2022 22:15:14
  • Zuletzt bearbeitet 21.11.2024 06:53:36

Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

Exploit
  • EPSS 0.53%
  • Veröffentlicht 04.02.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:59

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.

Exploit
  • EPSS 25.81%
  • Veröffentlicht 04.02.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:59

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 04.02.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:58

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.