Totolink X5000R Firmware vulnerabilities

70 known vulnerabilities affecting totolink/x5000r_firmware.

Total CVEs
70
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH38MEDIUM10

Vulnerabilities

Page 2 of 4
CVE-2024-57023MEDIUMCVSS 6.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57023 [MEDIUM] CWE-78 CVE-2024-57023: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.
nvd
CVE-2024-57025MEDIUMCVSS 6.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57025 [MEDIUM] CWE-78 CVE-2024-57025: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg.
nvd
CVE-2024-57024MEDIUMCVSS 6.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57024 [MEDIUM] CWE-78 CVE-2024-57024: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.
nvd
CVE-2024-42736HIGHCVSS 7.8v9.1.0cu.2350_b202303132024-08-13
CVE-2024-42736 [HIGH] CWE-78 CVE-2024-42736: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42739HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-13
CVE-2024-42739 [HIGH] CWE-78 CVE-2024-42739: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42738HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-13
CVE-2024-42738 [HIGH] CWE-78 CVE-2024-42738: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42737HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-13
CVE-2024-42737 [HIGH] CWE-78 CVE-2024-42737: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42740MEDIUMCVSS 6.8v9.1.0cu.2350_b202303132024-08-13
CVE-2024-42740 [MEDIUM] CWE-78 CVE-2024-42740: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42744HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42744 [HIGH] CWE-78 CVE-2024-42744: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUser. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42747HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42747 [HIGH] CWE-78 CVE-2024-42747: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42741HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42741 [HIGH] CWE-78 CVE-2024-42741: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42745HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42745 [HIGH] CWE-78 CVE-2024-42745: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42748HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42748 [HIGH] CWE-78 CVE-2024-42748: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42742HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42742 [HIGH] CWE-78 CVE-2024-42742: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-42743HIGHCVSS 8.8v9.1.0u.6369_b202301132024-08-12
CVE-2024-42743 [HIGH] CWE-78 CVE-2024-42743: In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command inj In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenticated Attackers can send malicious packet to execute arbitrary commands.
nvd
CVE-2024-32353CRITICALCVSS 9.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32353 [CRITICAL] CWE-77 CVE-2024-32353: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
nvd
CVE-2024-34921HIGHCVSS 8.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-34921 [HIGH] CWE-78 CVE-2024-34921: TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the discon TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.
nvd
CVE-2024-32355HIGHCVSS 8.0v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32355 [HIGH] CWE-77 CVE-2024-32355: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.
nvd
CVE-2024-32350HIGHCVSS 8.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32350 [HIGH] CWE-94 CVE-2024-32350: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command ex TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.
nvd
CVE-2024-32352HIGHCVSS 8.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32352 [HIGH] CWE-94 CVE-2024-32352: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command ex TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.
nvd