cbcvebase.

Totolink X5000R Firmware vulnerabilities

70 known vulnerabilities affecting totolink/x5000r_firmware.

Total CVEs
70
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL24HIGH38MEDIUM8

Vulnerabilities

Page 2 of 4
CVE-2024-42748P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42748 [HIGH] CWE-78 CVE-2024-42748: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42739P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-13
CVE-2024-42739 [HIGH] CWE-78 CVE-2024-42739: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42744P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42744 [HIGH] CWE-78 CVE-2024-42744: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUser. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42742P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42742 [HIGH] CWE-78 CVE-2024-42742: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-57011P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57011 [HIGH] CWE-78 CVE-2024-57011: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.
nvd
CVE-2024-42738P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-13
CVE-2024-42738 [HIGH] CWE-78 CVE-2024-42738: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42743P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42743 [HIGH] CWE-78 CVE-2024-42743: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-57018P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57018 [HIGH] CWE-78 CVE-2024-57018: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg.
nvd
CVE-2024-57019P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57019 [HIGH] CWE-78 CVE-2024-57019: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg.
nvd
CVE-2024-57021P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57021 [HIGH] CWE-78 CVE-2024-57021: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg.
nvd
CVE-2024-57020P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57020 [HIGH] CWE-78 CVE-2024-57020: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiScheduleCfg.
nvd
CVE-2024-57013P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57013 [HIGH] CWE-78 CVE-2024-57013: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg.
nvd
CVE-2024-57012P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57012 [HIGH] CWE-78 CVE-2024-57012: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg.
nvd
CVE-2024-57022P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57022 [HIGH] CWE-78 CVE-2024-57022: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleCfg.
nvd
CVE-2024-57016P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57016 [HIGH] CWE-78 CVE-2024-57016: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg.
nvd
CVE-2024-57015P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57015 [HIGH] CWE-78 CVE-2024-57015: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.
nvd
CVE-2023-39617P2CRITICALCVSS 9.8v9.1.0cu.2089_b20211224v9.1.0cu.2350_b202303132023-08-21
CVE-2023-39617 [CRITICAL] CWE-77 CVE-2023-39617: TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contai TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
nvd
CVE-2024-57017P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57017 [HIGH] CWE-78 CVE-2024-57017: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.
nvd
CVE-2024-57014P2HIGHCVSS 8.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57014 [HIGH] CWE-78 CVE-2024-57014: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg.
nvd
CVE-2024-42741P2HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42741 [HIGH] CWE-78 CVE-2024-42741: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd