Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TOTOLINK — Vulnerabilities & Security Advisories 506

Browse all 506 CVE security advisories affecting TOTOLINK. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TOTOLINK operates primarily as a manufacturer of consumer networking hardware, including wireless routers and range extenders, targeting residential and small business markets. Security audits reveal a significant volume of vulnerabilities, with 429 CVEs currently documented, indicating systemic issues in firmware development and code review processes. Historically, the most prevalent flaw classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation bugs, often stemming from inadequate input validation and weak authentication mechanisms in web management interfaces. These defects frequently allow unauthenticated attackers to gain full administrative control or execute arbitrary commands on affected devices. While no single catastrophic global incident has been widely publicized, the sheer quantity of disclosed vulnerabilities suggests a consistent pattern of security negligence. Users are advised to exercise caution, as the vendor’s response to patching these critical flaws has been inconsistent, leaving many deployed units exposed to exploitation.

CVE ID Title CVSS Severity Published
CVE-2025-7758 TOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg buffer overflow — T6 CWE-120 8.8 High 2025-07-17
CVE-2025-7615 TOTOLINK T6 HTTP POST Request cstecgi.cgi clearPairCfg command injection — T6 CWE-77 6.3 Medium 2025-07-14
CVE-2025-7614 TOTOLINK T6 HTTP POST Request cstecgi.cgi delDevice command injection — T6 CWE-77 6.3 Medium 2025-07-14
CVE-2025-7613 TOTOLINK T6 HTTP POST Request cstecgi.cgi CloudSrvVersionCheck command injection — T6 CWE-77 6.3 Medium 2025-07-14
CVE-2025-7525 TOTOLINK T6 HTTP POST Request cstecgi.cgi setTracerouteCfg command injection — T6 CWE-77 6.3 Medium 2025-07-13
CVE-2025-7524 TOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg command injection — T6 CWE-77 6.3 Medium 2025-07-13
CVE-2025-7460 TOTOLINK T6 HTTP POST Request cstecgi.cgi setWiFiAclRules buffer overflow — T6 CWE-120 8.8 High 2025-07-11
CVE-2025-7154 TOTOLINK N200RE cstecgi.cgi sub_41A0F8 os command injection — N200RE CWE-78 6.3 Medium 2025-07-08
CVE-2025-6953 TOTOLINK A3002RU HTTP POST Request formParentControl buffer overflow — A3002RU CWE-120 8.8 High 2025-07-01
CVE-2025-6940 TOTOLINK A702R HTTP POST Request formParentControl buffer overflow — A702R CWE-120 8.8 High 2025-07-01
CVE-2025-6939 TOTOLINK A3002RU HTTP POST Request formWlSiteSurvey buffer overflow — A3002RU CWE-120 8.8 High 2025-07-01
CVE-2025-6916 TOTOLINK T6 formLoginAuth.htm Form_Login missing authentication — T6 CWE-306 8.8 High 2025-06-30
CVE-2025-6825 TOTOLINK A702R HTTP POST Request formWlSiteSurvey buffer overflow — A702R CWE-120 8.8 High 2025-06-28
CVE-2025-6824 TOTOLINK X15 HTTP POST Request formParentControl buffer overflow — X15 CWE-120 8.8 High 2025-06-28
CVE-2025-6627 TOTOLINK A702R HTTP POST Request formIpv6Setup buffer overflow — A702R CWE-120 8.8 High 2025-06-25
CVE-2025-6621 TOTOLINK CA300-PoE ap.so QuickSetting os command injection — CA300-PoE CWE-78 6.3 Medium 2025-06-25
CVE-2025-6620 TOTOLINK CA300-PoE upgrade.so setUpgradeUboot os command injection — CA300-PoE CWE-78 6.3 Medium 2025-06-25
CVE-2025-6619 TOTOLINK CA300-PoE upgrade.so setUpgradeFW os command injection — CA300-PoE CWE-78 6.3 Medium 2025-06-25
CVE-2025-6618 TOTOLINK CA300-PoE wps.so SetWLanApcliSettings os command injection — CA300-PoE CWE-78 6.3 Medium 2025-06-25
CVE-2025-6568 TOTOLINK EX1200T HTTP POST Request formIpv6Setup buffer overflow — EX1200T CWE-120 8.8 High 2025-06-24
CVE-2025-6487 TOTOLINK A3002R formRoute stack-based overflow — A3002R CWE-121 8.8 High 2025-06-22
CVE-2025-6486 TOTOLINK A3002R formWlanMultipleAP stack-based overflow — A3002R CWE-121 8.8 High 2025-06-22
CVE-2025-6485 TOTOLINK A3002R formWlSiteSurvey os command injection — A3002R CWE-78 6.3 Medium 2025-06-22
CVE-2025-6402 TOTOLINK X15 HTTP POST Request formIpv6Setup buffer overflow — X15 CWE-120 8.8 High 2025-06-21
CVE-2025-6401 TOTOLINK N300RH HTTP POST Message formFilter denial of service — N300RH CWE-404 3.5 Low 2025-06-21
CVE-2025-6400 TOTOLINK N300RH HTTP POST Message formPortFw buffer overflow — N300RH CWE-120 8.8 High 2025-06-21
CVE-2025-6399 TOTOLINK X15 HTTP POST Request formIPv6Addr buffer overflow — X15 CWE-120 8.8 High 2025-06-21
CVE-2025-6393 TOTOLINK A702R/A3002R/A3002RU/EX1200T HTTP POST Request formIPv6Addr buffer overflow — A702R CWE-120 8.8 High 2025-06-21
CVE-2025-6337 TOTOLINK A3002R/A3002RU HTTP POST Request formTmultiAP buffer overflow — A3002R CWE-120 8.8 High 2025-06-20
CVE-2025-6336 TOTOLINK EX1200T HTTP POST Request formTmultiAP buffer overflow — EX1200T CWE-120 8.8 High 2025-06-20

This page lists every published CVE security advisory associated with TOTOLINK. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.