VendorsTOTOLINKa6000rany version
Vulnerabilities

TOTOLINK A6000R any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2024-41319
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.
Published 2024-07-23 · Modified
9.8EPSS 0.055
CVE-2025-3249
TOTOLINK A6000R mtkwifi.lua apcli_cancel_wps command injection
Published 2025-04-04 · Analyzed
9.8EPSS 0.028
CVE-2024-41316
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
Published 2024-07-22 · Analyzed
9.8EPSS 0.025
CVE-2024-41318
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
Published 2024-07-22 · Analyzed
9.8EPSS 0.024
CVE-2024-41320
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info function.
Published 2024-07-22 · Analyzed
8.8EPSS 0.022
CVE-2024-37626
A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the vif_enable function.
Published 2024-06-20 · Modified
8.8EPSS 0.015
CVE-2024-41317
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
Published 2024-07-22 · Analyzed
8.0EPSS 0.023
CVE-2024-57211
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.
Published 2025-01-10 · Analyzed
8.0EPSS 0.012
CVE-2024-41315
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.
Published 2024-07-22 · Analyzed
6.8EPSS 0.021
CVE-2024-41314
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.
Published 2024-07-22 · Analyzed
6.8EPSS 0.021
CVE-2024-57213
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function.
Published 2025-01-10 · Analyzed
6.3EPSS 0.007
CVE-2024-57214
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
Published 2025-01-10 · Analyzed
6.3EPSS 0.007
CVE-2024-57212
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.
Published 2025-01-10 · Analyzed
5.1EPSS 0.008