Totolink X5000R Firmware vulnerabilities

70 known vulnerabilities affecting totolink/x5000r_firmware.

Total CVEs
70
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH38MEDIUM10

Vulnerabilities

Page 3 of 4
CVE-2024-32351HIGHCVSS 8.8v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32351 [HIGH] CWE-78 CVE-2024-32351: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command ex TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.
nvd
CVE-2024-32354MEDIUMCVSS 6.0v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32354 [MEDIUM] CWE-77 CVE-2024-32354: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
nvd
CVE-2024-32349MEDIUMCVSS 6.0v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32349 [MEDIUM] CWE-77 CVE-2024-32349: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command ex TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.
nvd
CVE-2024-28639CRITICALCVSS 9.8v9.1.0u.6118_b202011022024-03-16
CVE-2024-28639 [CRITICAL] CWE-120 CVE-2024-28639: Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B202 Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.
nvd
CVE-2024-28640HIGHCVSS 7.5v9.1.0u.6118_b202011022024-03-16
CVE-2024-28640 [HIGH] CWE-125 CVE-2024-28640: Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B202 Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.
nvd
CVE-2024-25468HIGHCVSS 7.5v9.1.0u.6369_b202301132024-02-17
CVE-2024-25468 [HIGH] CWE-78 CVE-2024-25468: An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of se An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.
nvd
CVE-2023-6612CRITICALCVSS 9.8v9.1.0cu.2300_b202301122023-12-08
CVE-2023-6612 [CRITICAL] CWE-78 CVE-2023-6612: A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDynamicRoute/setFirewallType/setIPSecCfg/setIpPortFilterRules/setLancfg/setLoginPasswordCfg/setMacFilterRules/setMtknatCfg/setNetworkConfig/setPortForwardRules/setRemoteCfg/setSSServer/setScheduleCfg/setSmar
nvd
CVE-2023-45984CRITICALCVSS 9.8v9.1.0u.6118_b202011022023-10-16
CVE-2023-45984 [CRITICAL] CWE-787 CVE-2023-45984: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.
nvd
CVE-2023-36947CRITICALCVSS 9.8v9.1.0u.6118_b202011022023-10-16
CVE-2023-36947 [CRITICAL] CWE-787 CVE-2023-36947: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
nvd
CVE-2023-36950CRITICALCVSS 9.8v9.1.0u.6118_b202011022023-10-16
CVE-2023-36950 [CRITICAL] CWE-787 CVE-2023-36950: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
nvd
CVE-2023-45985HIGHCVSS 7.5v9.1.0u.6118_b202011022023-10-16
CVE-2023-45985 [HIGH] CWE-787 CVE-2023-45985: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2023-39618CRITICALCVSS 9.8vb202104192023-08-21
CVE-2023-39618 [CRITICAL] CWE-77 CVE-2023-39618: TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.
nvd
CVE-2023-39617CRITICALCVSS 9.8v9.1.0cu.2089_b20211224v9.1.0cu.2350_b202303132023-08-21
CVE-2023-39617 [CRITICAL] CWE-77 CVE-2023-39617: TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contai TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
nvd
CVE-2023-31569CRITICALCVSS 9.8v9.1.0cu.2350_b202303132023-06-06
CVE-2023-31569 [CRITICAL] CWE-77 CVE-2023-31569: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWan TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
nvd
CVE-2023-33486CRITICALCVSS 9.8v9.1.0u.6118_b20201102v9.1.0u.6369_b202301132023-05-31
CVE-2023-33486 [CRITICAL] CWE-77 CVE-2023-33486: TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulner TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.
nvd
CVE-2023-33487CRITICALCVSS 9.8v9.1.0u.6118_b20201102v9.1.0u.6369_b202301132023-05-31
CVE-2023-33487 [CRITICAL] CWE-77 CVE-2023-33487: TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulne TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.
nvd
CVE-2023-33485HIGHCVSS 8.8v9.1.0u.6118_b20201102v9.1.0u.6369_b202301132023-05-31
CVE-2023-33485 [HIGH] CWE-787 CVE-2023-33485: TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buf TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.
nvd
CVE-2023-30013CRITICALCVSS 9.8PoCv9.1.0u.6118_b20201102v9.1.0u.6369_b202301132023-05-05
CVE-2023-30013 [CRITICAL] CWE-78 CVE-2023-30013: TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulner TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
nvd
CVE-2022-27005CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-03-15
CVE-2022-27005 [CRITICAL] CWE-78 CVE-2022-27005: Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered t Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2022-26213CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-03-15
CVE-2022-26213 [CRITICAL] CWE-78 CVE-2022-26213: Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulner Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd