Totolink Ex1200T Firmware vulnerabilities
37 known vulnerabilities affecting totolink/ex1200t_firmware.
Total CVEs
37
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH24MEDIUM1
Vulnerabilities
Page 2 of 2
CVE-2025-28038CRITICALCVSS 9.8v4.1.2cu.5232_b202107132025-04-22
CVE-2025-28038 [CRITICAL] CWE-78 CVE-2025-28038: TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vu
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.
nvd
CVE-2025-28039CRITICALCVSS 9.8v4.1.2cu.5232_b202107132025-04-22
CVE-2025-28039 [CRITICAL] CWE-78 CVE-2025-28039: TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vu
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.
nvd
CVE-2023-52032CRITICALCVSS 9.8v4.1.2cu.5232_b202107132024-01-11
CVE-2023-52032 [CRITICAL] CVE-2023-52032: TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE)
TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.
nvd
CVE-2021-42884CRITICALCVSS 9.8v4.1.2cu.52152022-06-03
CVE-2021-42884 [CRITICAL] CWE-78 CVE-2021-42884: TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDevi
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control thedeviceName to attack.
nvd
CVE-2021-42888CRITICALCVSS 9.8v4.1.2cu.52152022-06-03
CVE-2021-42888 [CRITICAL] CWE-78 CVE-2021-42888: TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLang
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack.
nvd
CVE-2021-42890CRITICALCVSS 9.8v4.1.2cu.52152022-06-03
CVE-2021-42890 [CRITICAL] CWE-78 CVE-2021-42890: TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSync
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.
nvd
CVE-2021-42887CRITICALCVSS 9.8PoCv4.1.2cu.52152022-06-03
CVE-2021-42887 [CRITICAL] CVE-2021-42887: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request throug
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
nvd
CVE-2021-42885CRITICALCVSS 9.8v4.1.2cu.52152022-06-03
CVE-2021-42885 [CRITICAL] CWE-78 CVE-2021-42885: TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDevi
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can control deviceName to attack.
nvd
CVE-2021-42893HIGHCVSS 7.5v4.1.2cu.52152022-06-03
CVE-2021-42893 [HIGH] CWE-306 CVE-2021-42893: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) with
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.
nvd
CVE-2021-42886HIGHCVSS 7.5v4.1.2cu.52152022-06-03
CVE-2021-42886 [HIGH] CWE-200 CVE-2021-42886: TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker ca
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file.
nvd
CVE-2021-42891HIGHCVSS 7.5v4.1.2cu.52152022-06-03
CVE-2021-42891 [HIGH] CWE-306 CVE-2021-42891: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) with
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
nvd
CVE-2021-42889HIGHCVSS 7.5v4.1.2cu.52152022-06-03
CVE-2021-42889 [HIGH] CWE-306 CVE-2021-42889: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname,
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.
nvd
CVE-2021-42892MEDIUMCVSS 4.3v4.1.2cu.52152022-06-03
CVE-2021-42892 [MEDIUM] CWE-798 CVE-2021-42892: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the de
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.
nvd
CVE-2021-42875CRITICALCVSS 9.8v4.1.2cu.52152022-06-02
CVE-2021-42875 [CRITICAL] CWE-78 CVE-2021-42875: TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function set
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
nvd
CVE-2021-42872CRITICALCVSS 9.8v4.1.2cu.52152022-06-02
CVE-2021-42872 [CRITICAL] CWE-78 CVE-2021-42872: TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely ex
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.
nvd
CVE-2021-42877HIGHCVSS 7.5v4.1.2cu.52152022-06-02
CVE-2021-42877 [HIGH] CVE-2021-42877: TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem o
TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.
nvd
CVE-2022-25008HIGHCVSS 8.8v4.1.2cu.5230_b202107062022-03-30
CVE-2022-25008 [HIGH] CWE-306 CVE-2022-25008: totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an auth
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
nvd
← Previous2 / 2