cbcvebase.

Totolink Cp300 + Firmware vulnerabilities

6 known vulnerabilities affecting totolink/cp300_+_firmware.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH1

Vulnerabilities

Page 1 of 1
CVE-2023-31856P2CRITICALCVSS 9.8v5.2cu.7594_b202009102023-05-16
CVE-2023-31856 [CRITICAL] CWE-77 CVE-2023-31856: A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLI A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
nvd
CVE-2023-36952P2CRITICALCVSS 9.8v5.2cu.7594_b202009102023-10-16
CVE-2023-36952 [CRITICAL] CWE-787 CVE-2023-36952: TOTOLINK CP300+ V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the pingIp para TOTOLINK CP300+ V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the pingIp parameter in the function setDiagnosisCfg.
nvd
CVE-2023-36954P2CRITICALCVSS 9.8v5.2cu.7594_b202009102023-10-16
CVE-2023-36954 [CRITICAL] CWE-77 CVE-2023-36954: TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection. TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
nvd
CVE-2023-36953P2CRITICALCVSS 9.8v5.2cu.7594_b202009102023-10-16
CVE-2023-36953 [CRITICAL] CWE-77 CVE-2023-36953: TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection. TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
nvd
CVE-2023-36955P3CRITICALCVSS 9.8≤ 5.2cu.7594_b202009102023-10-16
CVE-2023-36955 [CRITICAL] CWE-787 CVE-2023-36955: TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File para TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
nvd
CVE-2023-34669P4HIGHCVSS 7.5v5.2cu.75942023-07-17
CVE-2023-34669 [HIGH] CWE-203 CVE-2023-34669: TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of t TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.
nvd
Totolink Cp300 + Firmware vulnerabilities | cvebase