CVE-2025-25605
- EPSS 0.78%
- Veröffentlicht 21.02.2025 19:15:14
- Zuletzt bearbeitet 04.04.2025 15:29:44
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.
CVE-2025-25604
- EPSS 0.78%
- Veröffentlicht 21.02.2025 19:15:14
- Zuletzt bearbeitet 04.04.2025 15:30:47
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
CVE-2024-57025
- EPSS 1.35%
- Veröffentlicht 15.01.2025 17:15:18
- Zuletzt bearbeitet 07.04.2025 18:08:31
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg.
CVE-2024-57024
- EPSS 1.51%
- Veröffentlicht 15.01.2025 17:15:18
- Zuletzt bearbeitet 07.04.2025 18:10:29
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.
CVE-2024-57023
- EPSS 1.35%
- Veröffentlicht 15.01.2025 17:15:18
- Zuletzt bearbeitet 07.04.2025 18:14:48
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.
CVE-2024-32352
- EPSS 2.18%
- Veröffentlicht 14.05.2024 16:17:03
- Zuletzt bearbeitet 04.04.2025 14:28:01
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.
CVE-2024-32353
- EPSS 2.09%
- Veröffentlicht 14.05.2024 16:17:03
- Zuletzt bearbeitet 04.04.2025 14:27:54
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.