CVE-2025-28039
- EPSS 3.85%
- Published 22.04.2025 00:00:00
- Last modified 29.04.2025 16:01:14
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.
CVE-2025-28038
- EPSS 4.24%
- Published 22.04.2025 00:00:00
- Last modified 29.04.2025 16:02:01
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.
CVE-2023-52032
- EPSS 14.39%
- Published 11.01.2024 09:15:47
- Last modified 17.06.2025 15:15:37
TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.
CVE-2021-42893
- EPSS 0.63%
- Published 03.06.2022 18:15:08
- Last modified 21.11.2024 06:28:17
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.
- EPSS 0.14%
- Published 03.06.2022 17:15:07
- Last modified 21.11.2024 06:28:17
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.
CVE-2021-42891
- EPSS 0.69%
- Published 03.06.2022 16:15:11
- Last modified 21.11.2024 06:28:17
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
CVE-2021-42889
- EPSS 0.91%
- Published 03.06.2022 15:15:08
- Last modified 21.11.2024 06:28:16
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.
CVE-2021-42890
- EPSS 3.34%
- Published 03.06.2022 15:15:08
- Last modified 21.11.2024 06:28:17
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.
CVE-2021-42888
- EPSS 3.34%
- Published 03.06.2022 14:15:08
- Last modified 21.11.2024 06:28:16
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack.
CVE-2021-42887
- EPSS 62.85%
- Published 03.06.2022 12:15:07
- Last modified 21.11.2024 06:28:16
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.