Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TOTOLINK — Vulnerabilities & Security Advisories 506

Browse all 506 CVE security advisories affecting TOTOLINK. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TOTOLINK operates primarily as a manufacturer of consumer networking hardware, including wireless routers and range extenders, targeting residential and small business markets. Security audits reveal a significant volume of vulnerabilities, with 429 CVEs currently documented, indicating systemic issues in firmware development and code review processes. Historically, the most prevalent flaw classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation bugs, often stemming from inadequate input validation and weak authentication mechanisms in web management interfaces. These defects frequently allow unauthenticated attackers to gain full administrative control or execute arbitrary commands on affected devices. While no single catastrophic global incident has been widely publicized, the sheer quantity of disclosed vulnerabilities suggests a consistent pattern of security negligence. Users are advised to exercise caution, as the vendor’s response to patching these critical flaws has been inconsistent, leaving many deployed units exposed to exploitation.

CVE ID Title CVSS Severity Published
CVE-2023-7222 Totolink X2000R HTTP POST Request boa formTmultiAP buffer overflow — X2000R CWE-120 7.2 High 2024-01-09
CVE-2023-7221 Totolink T6 HTTP POST Request main buffer overflow — T6 CWE-120 9.8 Critical 2024-01-09
CVE-2023-7220 Totolink NR1800X cstecgi.cgi loginAuth stack-based overflow — NR1800X CWE-121 9.8 Critical 2024-01-09
CVE-2023-7219 Totolink N350RT cstecgi.cgi loginAuth stack-based overflow — N350RT CWE-121 7.2 High 2024-01-09
CVE-2023-7218 Totolink N350RT cstecgi.cgi loginAuth stack-based overflow — N350RT CWE-121 7.2 High 2024-01-08
CVE-2024-0299 Totolink N200RE cstecgi.cgi setTracerouteCfg os command injection — N200RE CWE-78 7.3 High 2024-01-08
CVE-2024-0298 Totolink N200RE cstecgi.cgi setDiagnosisCfg os command injection — N200RE CWE-78 7.3 High 2024-01-08
CVE-2024-0297 Totolink N200RE cstecgi.cgi UploadFirmwareFile os command injection — N200RE CWE-78 7.3 High 2024-01-08
CVE-2024-0296 Totolink N200RE cstecgi.cgi NTPSyncWithHost os command injection — N200RE CWE-78 7.3 High 2024-01-08
CVE-2024-0295 Totolink LR1200GB cstecgi.cgi setWanCfg os command injection — LR1200GB CWE-78 7.3 High 2024-01-08
CVE-2024-0294 Totolink LR1200GB cstecgi.cgi setUssd os command injection — LR1200GB CWE-78 7.3 High 2024-01-08
CVE-2024-0293 Totolink LR1200GB cstecgi.cgi setUploadSetting os command injection — LR1200GB CWE-78 6.3 Medium 2024-01-08
CVE-2024-0292 Totolink LR1200GB cstecgi.cgi setOpModeCfg os command injection — LR1200GB CWE-78 6.3 Medium 2024-01-08
CVE-2024-0291 Totolink LR1200GB cstecgi.cgi UploadFirmwareFile command injection — LR1200GB CWE-77 6.3 Medium 2024-01-08
CVE-2023-7214 Totolink N350RT HTTP POST Request main stack-based overflow — N350RT CWE-121 6.3 Medium 2024-01-07
CVE-2023-7213 Totolink N350RT HTTP POST Request main stack-based overflow — N350RT CWE-121 6.3 Medium 2024-01-07
CVE-2023-7208 Totolink X2000R_V2 boa formTmultiAP buffer overflow — X2000R_V2 CWE-120 8.0 High 2024-01-07
CVE-2023-7187 Totolink N350RT HTTP POST Request stack-based overflow — N350RT CWE-121 5.5 Medium 2023-12-31
CVE-2023-7095 Totolink A7100RU HTTP POST Request main buffer overflow — A7100RU CWE-120 9.8 Critical 2023-12-25
CVE-2023-6906 Totolink A7100RU HTTP POST Request main buffer overflow — A7100RU CWE-120 9.8 Critical 2023-12-18
CVE-2023-6612 Totolink X5000R cstecgi.cgi setWizardCfg os command injection — X5000R CWE-78 5.5 Medium 2023-12-08
CVE-2023-4746 TOTOLINK N200RE V5 Validity_check format string — N200RE V5 CWE-134 8.8 High 2023-09-04
CVE-2023-4412 TOTOLINK EX1200L setWanCfg os command injection — EX1200L CWE-78 6.3 Medium 2023-08-18
CVE-2023-4411 TOTOLINK EX1200L setTracerouteCfg os command injection — EX1200L CWE-78 6.3 Medium 2023-08-18
CVE-2023-4410 TOTOLINK EX1200L setDiagnosisCfg os command injection — EX1200L CWE-78 6.3 Medium 2023-08-18
CVE-2023-2790 TOTOLINK N200RE Telnet Service custom.conf password in configuration file — N200RE CWE-260 2.3 Low 2023-05-18

This page lists every published CVE security advisory associated with TOTOLINK. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.