Totolink Ex1200T Firmware vulnerabilities
37 known vulnerabilities affecting totolink/ex1200t_firmware.
Total CVEs
37
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH21MEDIUM4
Vulnerabilities
Page 2 of 2
CVE-2025-6144P2HIGHCVSS 8.8v4.1.2cu.5232_b202107132025-06-16
CVE-2025-6144 [HIGH] CWE-119 CVE-2025-6144: A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical
A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formSysCmd of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit
nvd
CVE-2025-6143P2HIGHCVSS 8.8v4.1.2cu.5232_b202107132025-06-16
CVE-2025-6143 [HIGH] CWE-119 CVE-2025-6143: A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formNtp of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed
nvd
CVE-2025-51451P2CRITICALCVSS 9.8v4.1.2cu.52152025-08-13
CVE-2025-51451 [CRITICAL] CWE-287 CVE-2025-51451: In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific reques
In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
nvd
CVE-2025-28038P2CRITICALCVSS 9.8v4.1.2cu.5232_b202107132025-04-22
CVE-2025-28038 [CRITICAL] CWE-78 CVE-2025-28038: TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vu
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.
nvd
CVE-2025-28039P2CRITICALCVSS 9.8v4.1.2cu.5232_b202107132025-04-22
CVE-2025-28039 [CRITICAL] CWE-78 CVE-2025-28039: TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vu
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.
nvd
CVE-2023-52032P3CRITICALCVSS 9.8v4.1.2cu.5232_b202107132024-01-11
CVE-2023-52032 [CRITICAL] CVE-2023-52032: TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE)
TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.
nvd
CVE-2022-25008P3HIGHCVSS 8.8v4.1.2cu.5230_b202107062022-03-30
CVE-2022-25008 [HIGH] CWE-306 CVE-2022-25008: totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an auth
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
nvd
CVE-2025-6393P3HIGHCVSS 7.5v4.1.2cu.5232_b202107132025-06-21
CVE-2025-6393 [HIGH] CWE-119 CVE-2025-6393: A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-
A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads
nvd
CVE-2025-5792P3MEDIUMCVSS 6.5v4.1.2cu.5232_b202107132025-06-06
CVE-2025-5792 [MEDIUM] CWE-119 CVE-2025-5792: A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of the argument redirect-url leads to buffer overflow. The attack may be initiated remotely. The explo
nvd
CVE-2025-6336P3MEDIUMCVSS 6.5v4.1.2cu.5232_b202107132025-06-20
CVE-2025-6336 [MEDIUM] CWE-119 CVE-2025-6336: A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. It has been classified as crit
A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been d
nvd
CVE-2025-5793P3MEDIUMCVSS 6.5v4.1.2cu.5232_b202107132025-06-06
CVE-2025-5793 [MEDIUM] CWE-119 CVE-2025-5793: A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been di
nvd
CVE-2021-42886P3HIGHCVSS 7.5v4.1.2cu.52152022-06-03
CVE-2021-42886 [HIGH] CWE-200 CVE-2021-42886: TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker ca
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file.
nvd
CVE-2021-42893P3HIGHCVSS 7.5v4.1.2cu.52152022-06-03
CVE-2021-42893 [HIGH] CWE-306 CVE-2021-42893: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) with
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.
nvd
CVE-2021-42891P3HIGHCVSS 7.5v4.1.2cu.52152022-06-03
CVE-2021-42891 [HIGH] CWE-306 CVE-2021-42891: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) with
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
nvd
CVE-2021-42889P3HIGHCVSS 7.5v4.1.2cu.52152022-06-03
CVE-2021-42889 [HIGH] CWE-306 CVE-2021-42889: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname,
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.
nvd
CVE-2021-42877P3HIGHCVSS 7.5v4.1.2cu.52152022-06-02
CVE-2021-42877 [HIGH] CVE-2021-42877: TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem o
TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.
nvd
CVE-2021-42892P4MEDIUMCVSS 4.3v4.1.2cu.52152022-06-03
CVE-2021-42892 [MEDIUM] CWE-798 CVE-2021-42892: In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the de
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.
nvd
← Previous2 / 2