Totolink Lr350 Firmware vulnerabilities
36 known vulnerabilities affecting totolink/lr350_firmware.
Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH22
Vulnerabilities
Page 2 of 2
CVE-2022-44258P3HIGHCVSS 8.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44258 [HIGH] CWE-787 CVE-2022-44258: TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter c
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.
nvd
CVE-2022-44253P3HIGHCVSS 8.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44253 [HIGH] CWE-787 CVE-2022-44253: TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter i
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.
nvd
CVE-2022-44255P3CRITICALCVSS 9.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44255 [CRITICAL] CWE-787 CVE-2022-44255: TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main func
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.
nvd
CVE-2024-42967P3CRITICALCVSS 9.8v9.3.5u.6369_b202203092024-08-15
CVE-2024-42967 [CRITICAL] CWE-284 CVE-2024-42967: Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apm
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
nvd
CVE-2022-44259P3HIGHCVSS 8.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44259 [HIGH] CWE-787 CVE-2022-44259: TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter w
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.
nvd
CVE-2022-44260P3HIGHCVSS 8.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44260 [HIGH] CWE-787 CVE-2022-44260: TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter s
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.
nvd
CVE-2022-44254P3HIGHCVSS 8.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44254 [HIGH] CWE-787 CVE-2022-44254: TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter t
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.
nvd
CVE-2022-44257P3HIGHCVSS 8.8v9.3.5u.6369_b202203092022-11-23
CVE-2022-44257 [HIGH] CWE-787 CVE-2022-44257: TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter p
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.
nvd
CVE-2024-34308P3HIGHCVSS 8.8v9.3.5u.6369_b202203092024-05-14
CVE-2024-34308 [HIGH] CWE-121 CVE-2024-34308: TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password pa
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.
nvd
CVE-2025-63466P3HIGHCVSS 7.5v9.3.5u.6369_b202203092025-10-31
CVE-2025-63466 [HIGH] CWE-121 CVE-2025-63466: Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password pa
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63469P3HIGHCVSS 7.5v9.3.5u.6369_b202203092025-10-31
CVE-2025-63469 [HIGH] CWE-121 CVE-2025-63469: Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parame
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63463P3HIGHCVSS 7.5v9.3.5u.6369_b202203092025-10-31
CVE-2025-63463 [HIGH] CWE-121 CVE-2025-63463: Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff par
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63467P3HIGHCVSS 7.5v9.3.5u.6369_b202203092025-10-31
CVE-2025-63467 [HIGH] CWE-121 CVE-2025-63467: Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parame
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63464P3HIGHCVSS 7.5v9.3.5u.6369_b202203092025-10-31
CVE-2025-63464 [HIGH] CWE-121 CVE-2025-63464: Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parame
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63468P3HIGHCVSS 7.5v9.3.5u.6369_b202203092025-10-31
CVE-2025-63468 [HIGH] CWE-121 CVE-2025-63468: Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host p
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63465P3HIGHCVSS 7.5v9.3.5u.6369_b202203092025-10-31
CVE-2025-63465 [HIGH] CWE-121 CVE-2025-63465: Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parame
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
← Previous2 / 2