cbcvebase.

Totolink Lr350 Firmware vulnerabilities

36 known vulnerabilities affecting totolink/lr350_firmware.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH22

Vulnerabilities

Page 1 of 2
CVE-2024-7214P1HIGHCVSS 8.8Exploitedv9.3.5u.6369_b202203092024-07-30
CVE-2024-7214 [HIGH] CWE-77 CVE-2024-7214: A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. A A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be use
nvd
CVE-2026-1149P2HIGHCVSS 8.8v9.3.5u.6369_b202203092026-01-19
CVE-2026-1149 [HIGH] CWE-74 CVE-2026-1149: A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the funct A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument ip leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-1150P2HIGHCVSS 8.8v9.3.5u.6369_b202203092026-01-19
CVE-2026-1150 [HIGH] CWE-74 CVE-2026-1150: A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the functio A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be us
nvd
CVE-2024-35387P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092024-05-24
CVE-2024-35387 [CRITICAL] CWE-121 CVE-2024-35387: TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host p TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
nvd
CVE-2026-1155P2HIGHCVSS 8.8v9.3.5u.6369_b202203092026-01-19
CVE-2026-1155 [HIGH] CWE-119 CVE-2026-1155: A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
nvd
CVE-2026-1157P2HIGHCVSS 8.8v9.3.5u.6369_b202203092026-01-19
CVE-2026-1157 [HIGH] CWE-119 CVE-2026-1157: A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function se A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-4976P2HIGHCVSS 8.8v9.3.5u.6369_b202203092026-03-27
CVE-2026-4976 [HIGH] CWE-119 CVE-2026-4976: A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the fu A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
nvd
CVE-2023-37148P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092023-07-07
CVE-2023-37148 [CRITICAL] CWE-77 CVE-2023-37148: TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability vi TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
nvd
CVE-2023-37145P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092023-07-07
CVE-2023-37145 [CRITICAL] CWE-77 CVE-2023-37145: TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability vi TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
nvd
CVE-2023-37149P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092023-07-07
CVE-2023-37149 [CRITICAL] CWE-77 CVE-2023-37149: TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability vi TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
nvd
CVE-2023-37146P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092023-07-07
CVE-2023-37146 [CRITICAL] CWE-77 CVE-2023-37146: TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability vi TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
nvd
CVE-2024-36783P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092024-06-03
CVE-2024-36783 [CRITICAL] CWE-77 CVE-2024-36783: TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_tim TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.
nvd
CVE-2026-1158P2HIGHCVSS 8.8v9.3.5u.6369_b202203092026-01-19
CVE-2026-1158 [HIGH] CWE-119 CVE-2026-1158: A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affe A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the pub
nvd
CVE-2026-1156P2HIGHCVSS 8.8v9.3.5u.6369_b202203092026-01-19
CVE-2026-1156 [HIGH] CWE-119 CVE-2026-1156: A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is th A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2022-44250P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44250 [CRITICAL] CWE-78 CVE-2022-44250: TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in t TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.
nvd
CVE-2022-44251P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44251 [CRITICAL] CWE-78 CVE-2022-44251: TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the s TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
nvd
CVE-2022-44249P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44249 [CRITICAL] CWE-78 CVE-2022-44249: TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in t TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.
nvd
CVE-2022-44252P2CRITICALCVSS 9.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44252 [CRITICAL] CWE-78 CVE-2022-44252: TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in t TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
nvd
CVE-2024-35099P2CRITICALCVSS 9.8v9.3.5u.6698_b202308102024-05-14
CVE-2024-35099 [CRITICAL] CWE-120 CVE-2024-35099: TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password pa TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.
nvd
CVE-2024-10654P2CRITICALCVSS 9.1v9.3.5u.6369_b202203092024-11-01
CVE-2024-10654 [CRITICAL] CWE-266 CVE-2024-10654: A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affec A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to th
nvd
Totolink Lr350 Firmware vulnerabilities | cvebase