cbcvebase.

Totolink X6000R Firmware vulnerabilities

57 known vulnerabilities affecting totolink/x6000r_firmware.

Total CVEs
57
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL48HIGH6MEDIUM3

Vulnerabilities

Page 2 of 3
CVE-2023-48801P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-12-01
CVE-2023-48801 [CRITICAL] CWE-77 CVE-2023-48801: In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fiel In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.
nvd
CVE-2023-48800P2CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-12-04
CVE-2023-48800 [CRITICAL] CWE-78 CVE-2023-48800: In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fiel In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.
nvd
CVE-2023-46421P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46421 [CRITICAL] CWE-77 CVE-2023-46421: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.
nvd
CVE-2023-46419P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46419 [CRITICAL] CWE-77 CVE-2023-46419: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.
nvd
CVE-2023-46424P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46424 [CRITICAL] CWE-77 CVE-2023-46424: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function.
nvd
CVE-2023-46415P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46415 [CRITICAL] CWE-77 CVE-2023-46415: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.
nvd
CVE-2023-46422P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46422 [CRITICAL] CWE-77 CVE-2023-46422: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.
nvd
CVE-2023-46417P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46417 [CRITICAL] CWE-77 CVE-2023-46417: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.
nvd
CVE-2023-46418P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46418 [CRITICAL] CWE-77 CVE-2023-46418: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.
nvd
CVE-2023-46420P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46420 [CRITICAL] CWE-77 CVE-2023-46420: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.
nvd
CVE-2023-46416P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46416 [CRITICAL] CWE-77 CVE-2023-46416: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.
nvd
CVE-2023-46423P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46423 [CRITICAL] CWE-77 CVE-2023-46423: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function.
nvd
CVE-2023-46414P2CRITICALCVSS 9.8v9.4.0cu.652_b202301162023-10-25
CVE-2023-46414 [CRITICAL] CWE-77 CVE-2023-46414: TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.
nvd
CVE-2023-50651P3CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-12-30
CVE-2023-50651 [CRITICAL] CWE-78 CVE-2023-50651: TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vu TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
nvd
CVE-2023-43455P3CRITICALCVSS 9.8v9.4.0cu.652_b20230116v9.4.0cu.852_b202307192023-12-01
CVE-2023-43455 [CRITICAL] CWE-77 CVE-2023-43455: An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attack An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracerouteCfg component.
nvd
CVE-2023-48799P3CRITICALCVSS 9.8v9.4.0cu.852_b202307192023-12-04
CVE-2023-48799 [CRITICAL] CVE-2023-48799: TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution. TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.
nvd
CVE-2023-43453P3CRITICALCVSS 9.8v9.4.0cu.652_b20230116v9.4.0cu.852_b202307192023-12-01
CVE-2023-43453 [CRITICAL] CWE-77 CVE-2023-43453: An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attack An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.
nvd
CVE-2023-52042P3CRITICALCVSS 9.8v9.4.0cu.852_b202307192024-01-16
CVE-2023-52042 [CRITICAL] CWE-77 CVE-2023-52042: An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attacker An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.
nvd
CVE-2023-52040P3CRITICALCVSS 9.8v9.4.0cu.852_b202307192024-01-24
CVE-2023-52040 [CRITICAL] CWE-77 CVE-2023-52040: An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary comm An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
nvd
CVE-2023-43454P3CRITICALCVSS 9.8v9.4.0cu.652_b20230116v9.4.0cu.852_b202307192023-12-01
CVE-2023-43454 [CRITICAL] CWE-77 CVE-2023-43454: An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attack An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component.
nvd