Show filters
610 Total Results
Displaying 301-310 of 610
Sort by:
Attacker Value
Unknown

CVE-2023-37146

Disclosure Date: July 07, 2023 (last updated February 25, 2025)
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
Attacker Value
Unknown

CVE-2023-37145

Disclosure Date: July 07, 2023 (last updated February 25, 2025)
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
Attacker Value
Unknown

CVE-2023-31569

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
Attacker Value
Unknown

CVE-2023-33487

Disclosure Date: May 31, 2023 (last updated February 25, 2025)
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.
Attacker Value
Unknown

CVE-2023-33486

Disclosure Date: May 31, 2023 (last updated February 25, 2025)
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.
Attacker Value
Unknown

CVE-2023-33485

Disclosure Date: May 31, 2023 (last updated February 25, 2025)
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.
Attacker Value
Unknown

CVE-2023-2790

Disclosure Date: May 18, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-229374 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-31729

Disclosure Date: May 18, 2023 (last updated February 25, 2025)
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
Attacker Value
Unknown

CVE-2023-31856

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
Attacker Value
Unknown

CVE-2023-30054

Disclosure Date: May 05, 2023 (last updated February 24, 2025)
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.