CVE-2025-4496
- EPSS 0.26%
- Published 10.05.2025 05:00:10
- Last modified 29.07.2025 14:42:19
A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The man...
CVE-2025-28017
- EPSS 3.72%
- Published 23.04.2025 00:00:00
- Last modified 06.05.2025 20:35:52
TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.
CVE-2025-28018
- EPSS 0.26%
- Published 23.04.2025 00:00:00
- Last modified 06.05.2025 20:35:45
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.
CVE-2025-28019
- EPSS 0.15%
- Published 23.04.2025 00:00:00
- Last modified 06.05.2025 20:35:39
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component
CVE-2025-28020
- EPSS 0.15%
- Published 23.04.2025 00:00:00
- Last modified 06.05.2025 20:35:33
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.
CVE-2025-28033
- EPSS 0.15%
- Published 22.04.2025 14:15:25
- Last modified 29.04.2025 16:19:19
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vu...
CVE-2025-28032
- EPSS 0.26%
- Published 22.04.2025 00:00:00
- Last modified 29.04.2025 16:19:28
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in...
CVE-2025-28034
- EPSS 3.25%
- Published 22.04.2025 00:00:00
- Last modified 29.04.2025 16:18:58
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command exe...
CVE-2025-28136
- EPSS 0.07%
- Published 15.04.2025 00:00:00
- Last modified 29.04.2025 16:22:52
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.
CVE-2025-28138
- EPSS 4.06%
- Published 27.03.2025 00:00:00
- Last modified 15.04.2025 15:16:08
The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.