Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown

CVE-2024-12352

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2023-52026

Disclosure Date: January 12, 2024 (last updated January 19, 2024)
TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface
Attacker Value
Unknown

CVE-2023-51022

Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.
Attacker Value
Unknown

CVE-2023-51021

Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.
Attacker Value
Unknown

CVE-2023-51020

Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langType’ parameter of the setLanguageCfg interface of the cstecgi .cgi.
Attacker Value
Unknown

CVE-2023-51019

Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘key5g’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.
Attacker Value
Unknown

CVE-2023-51018

Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi.
Attacker Value
Unknown

CVE-2023-51017

Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.
Attacker Value
Unknown

CVE-2023-51016

Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.
Attacker Value
Unknown

CVE-2023-51015

Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi