Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TOTOLINK — Vulnerabilities & Security Advisories 506

Browse all 506 CVE security advisories affecting TOTOLINK. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TOTOLINK operates primarily as a manufacturer of consumer networking hardware, including wireless routers and range extenders, targeting residential and small business markets. Security audits reveal a significant volume of vulnerabilities, with 429 CVEs currently documented, indicating systemic issues in firmware development and code review processes. Historically, the most prevalent flaw classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation bugs, often stemming from inadequate input validation and weak authentication mechanisms in web management interfaces. These defects frequently allow unauthenticated attackers to gain full administrative control or execute arbitrary commands on affected devices. While no single catastrophic global incident has been widely publicized, the sheer quantity of disclosed vulnerabilities suggests a consistent pattern of security negligence. Users are advised to exercise caution, as the vendor’s response to patching these critical flaws has been inconsistent, leaving many deployed units exposed to exploitation.

CVE ID Title CVSS Severity Published
CVE-2025-52905 TOTOLINK X6000R Argument Injection Vulnerability — X6000R CWE-20 7.5AI High AI 2025-09-23
CVE-2025-9935 TOTOLINK N600R cstecgi.cgi sub_4159F8 command injection — N600R CWE-77 7.3 High 2025-09-03
CVE-2025-9934 TOTOLINK X5000R cstecgi.cgi sub_410C34 command injection — X5000R CWE-77 6.3 Medium 2025-09-03
CVE-2025-9783 TOTOLINK A702R formParentControl sub_418030 buffer overflow — A702R CWE-120 8.8 High 2025-09-01
CVE-2025-9782 TOTOLINK A702R formOneKeyAccessButton sub_4466F8 buffer overflow — A702R CWE-120 8.8 High 2025-09-01
CVE-2025-9781 TOTOLINK A702R formFilter sub_4162DC buffer overflow — A702R CWE-120 8.8 High 2025-09-01
CVE-2025-9780 TOTOLINK A702R formIpQoS sub_419BE0 buffer overflow — A702R CWE-120 8.8 High 2025-09-01
CVE-2025-9779 TOTOLINK A702R formFilter sub_4162DC buffer overflow — A702R CWE-120 8.8 High 2025-09-01
CVE-2025-9577 TOTOLINK X2000R Administrative shadow.sample default credentials — X2000R CWE-1392 2.5 Low 2025-08-28
CVE-2025-9533 TOTOLINK T10 formLoginAuth.htm improper authentication — T10 CWE-287 7.3 High 2025-08-27
CVE-2025-9303 TOTOLINK A720R cstecgi.cgi setParentalRules buffer overflow — A720R CWE-120 8.8 High 2025-08-21
CVE-2025-8938 TOTOLINK N350R Telnet Service formSysTel backdoor — N350R CWE-912 6.3 Medium 2025-08-14
CVE-2025-8937 TOTOLINK N350R formSysCmd command injection — N350R CWE-77 6.3 Medium 2025-08-14
CVE-2025-8246 TOTOLINK X15 HTTP POST Request formRoute buffer overflow — X15 CWE-120 8.8 High 2025-07-27
CVE-2025-8245 TOTOLINK X15 HTTP POST Request formMultiAPVLAN buffer overflow — X15 CWE-120 8.8 High 2025-07-27
CVE-2025-8244 TOTOLINK X15 HTTP POST Request formMapDelDevice buffer overflow — X15 CWE-120 8.8 High 2025-07-27
CVE-2025-8243 TOTOLINK X15 HTTP POST Request formMapDel buffer overflow — X15 CWE-120 8.8 High 2025-07-27
CVE-2025-8242 TOTOLINK X15 HTTP POST Request formFilter buffer overflow — X15 CWE-120 8.8 High 2025-07-27
CVE-2025-8181 TOTOLINK N600R/X2000R FTP Service vsftpd.conf least privilege violation — N600R CWE-272 7.2 High 2025-07-26
CVE-2025-8170 TOTOLINK T6 MQTT Packet meshSlaveDlfw tcpcheck_net buffer overflow — T6 CWE-120 8.8 High 2025-07-25
CVE-2025-8140 TOTOLINK A702R HTTP POST Request formWlanMultipleAP buffer overflow — A702R CWE-120 8.8 High 2025-07-25
CVE-2025-8139 TOTOLINK A702R HTTP POST Request formPortFw buffer overflow — A702R CWE-120 8.8 High 2025-07-25
CVE-2025-8138 TOTOLINK A702R HTTP POST Request formOneKeyAccessButton buffer overflow — A702R CWE-120 8.8 High 2025-07-25
CVE-2025-8137 TOTOLINK A702R HTTP POST Request formIpQoS buffer overflow — A702R CWE-120 8.8 High 2025-07-25
CVE-2025-8136 TOTOLINK A702R HTTP POST Request formFilter buffer overflow — A702R CWE-120 8.8 High 2025-07-25
CVE-2025-7952 TOTOLINK T6 MQTT Packet wireless.so ckeckKeepAlive command injection — T6 CWE-77 6.3 Medium 2025-07-22
CVE-2025-7913 TOTOLINK T6 MQTT Service updateWifiInfo buffer overflow — T6 CWE-120 8.8 High 2025-07-20
CVE-2025-7912 TOTOLINK T6 MQTT Service recvSlaveUpgstatus buffer overflow — T6 CWE-120 8.8 High 2025-07-20
CVE-2025-7862 TOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authentication — T6 CWE-306 7.3 High 2025-07-20
CVE-2025-7837 TOTOLINK T6 MQTT Service recvSlaveStaInfo buffer overflow — T6 CWE-120 8.8 High 2025-07-19

This page lists every published CVE security advisory associated with TOTOLINK. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.