Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2024-10654
Disclosure Date: November 01, 2024 (last updated November 05, 2024)
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.3.5u.6698_B20230810 is able to address this issue. It is recommended to upgrade the affected component.
0
Attacker Value
Unknown
CVE-2024-42967
Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
0
Attacker Value
Unknown
CVE-2024-7214
Disclosure Date: July 30, 2024 (last updated August 07, 2024)
A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272785 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-37149
Disclosure Date: July 07, 2023 (last updated October 08, 2023)
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
0
Attacker Value
Unknown
CVE-2023-37148
Disclosure Date: July 07, 2023 (last updated October 08, 2023)
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
0
Attacker Value
Unknown
CVE-2023-37146
Disclosure Date: July 07, 2023 (last updated October 08, 2023)
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
0
Attacker Value
Unknown
CVE-2023-37145
Disclosure Date: July 07, 2023 (last updated October 08, 2023)
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
0
Attacker Value
Unknown
CVE-2022-44253
Disclosure Date: November 23, 2022 (last updated October 08, 2023)
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.
0
Attacker Value
Unknown
CVE-2022-44249
Disclosure Date: November 23, 2022 (last updated October 08, 2023)
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.
0
Attacker Value
Unknown
CVE-2022-44252
Disclosure Date: November 23, 2022 (last updated October 08, 2023)
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
0