Totolink X5000R Firmware vulnerabilities
70 known vulnerabilities affecting totolink/x5000r_firmware.
Total CVEs
70
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL24HIGH38MEDIUM8
Vulnerabilities
Page 4 of 4
CVE-2023-45985P3HIGHCVSS 7.5v9.1.0u.6118_b202011022023-10-16
CVE-2023-45985 [HIGH] CWE-787 CVE-2023-45985: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2021-45734P3HIGHCVSS 7.5v9.1.0u.6118_b202011022022-02-04
CVE-2021-45734 [HIGH] CVE-2021-45734: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function se
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via the url parameter.
nvd
CVE-2021-45741P3HIGHCVSS 7.5v9.1.0u.6118_b202011022022-02-04
CVE-2021-45741 [HIGH] CVE-2021-45741: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function se
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.
nvd
CVE-2024-57024P3MEDIUMCVSS 6.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57024 [MEDIUM] CWE-78 CVE-2024-57024: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.
nvd
CVE-2024-57023P3MEDIUMCVSS 6.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57023 [MEDIUM] CWE-78 CVE-2024-57023: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.
nvd
CVE-2024-57025P3MEDIUMCVSS 6.8v9.1.0cu.2350_b202303132025-01-15
CVE-2024-57025 [MEDIUM] CWE-78 CVE-2024-57025: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerabil
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg.
nvd
CVE-2021-45736P3HIGHCVSS 7.5v9.1.0u.6118_b202011022022-02-04
CVE-2021-45736 [HIGH] CVE-2021-45736: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function se
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.
nvd
CVE-2024-32354P3MEDIUMCVSS 6.0v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32354 [MEDIUM] CWE-77 CVE-2024-32354: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
nvd
CVE-2024-25468P4HIGHCVSS 7.5v9.1.0u.6369_b202301132024-02-17
CVE-2024-25468 [HIGH] CWE-78 CVE-2024-25468: An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of se
An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.
nvd
CVE-2024-32349P4MEDIUMCVSS 6.0v9.1.0cu.2350_b202303132024-05-14
CVE-2024-32349 [MEDIUM] CWE-77 CVE-2024-32349: TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command ex
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.
nvd
← Previous4 / 4