VendorsTOTOLINKex1200t_firmwareall versions
Vulnerabilities

TOTOLINK EX1200T Firmware 4.1.2cu.5230 B20210706

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2021-42872
TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.
Published 2022-05-31 · Modified
10.0EPSS 0.066
CVE-2021-42875
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
Published 2022-06-02 · Modified
10.0EPSS 0.044
CVE-2025-5600
TOTOLINK EX1200T cstecgi.cgi setLanguageCfg stack-based overflow
Published 2025-06-04 · Analyzed
10.0EPSS 0.012
CVE-2021-42887
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
Published 2022-06-03 · Modified
9.8EPSS 0.443
CVE-2021-42884
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control thedeviceName to attack.
Published 2022-06-03 · Modified
9.8EPSS 0.024
CVE-2021-42885
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can control deviceName to attack.
Published 2022-06-03 · Modified
9.8EPSS 0.024
CVE-2021-42888
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack.
Published 2022-06-03 · Modified
9.8EPSS 0.019
CVE-2021-42890
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.
Published 2022-06-03 · Modified
9.8EPSS 0.019
CVE-2023-52032
TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.
Published 2024-01-11 · Modified
9.8EPSS 0.016
CVE-2025-28039
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.
Published 2025-04-22 · Analyzed
9.8EPSS 0.012
CVE-2025-28038
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.
Published 2025-04-22 · Analyzed
9.8EPSS 0.012
CVE-2025-51451
In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
Published 2025-08-13 · Modified
9.8EPSS 0.004
CVE-2025-5907
TOTOLINK EX1200T HTTP POST Request formFilter buffer overflow
Published 2025-06-10 · Analyzed
9.0EPSS 0.062
CVE-2025-5792
TOTOLINK EX1200T HTTP POST Request formWlanRedirect buffer overflow
Published 2025-06-06 · Analyzed
9.0EPSS 0.058
CVE-2025-5909
TOTOLINK EX1200T HTTP POST Request formReflashClientTbl buffer overflow
Published 2025-06-10 · Analyzed
9.0EPSS 0.014
CVE-2025-6128
TOTOLINK EX1200T HTTP POST Request formWirelessTbl buffer overflow
Published 2025-06-16 · Analyzed
9.0EPSS 0.012
CVE-2025-5910
TOTOLINK EX1200T HTTP POST Request formWsc buffer overflow
Published 2025-06-10 · Analyzed
9.0EPSS 0.011
CVE-2025-5911
TOTOLINK EX1200T HTTP POST Request formDMZ buffer overflow
Published 2025-06-10 · Analyzed
9.0EPSS 0.011
CVE-2025-6393
TOTOLINK A702R/A3002R/A3002RU/EX1200T HTTP POST Request formIPv6Addr buffer overflow
Published 2025-06-21 · Analyzed
9.0EPSS 0.010
CVE-2025-5908
TOTOLINK EX1200T HTTP POST Request formIpQoS buffer overflow
Published 2025-06-10 · Analyzed
9.0EPSS 0.010
CVE-2025-6144
TOTOLINK EX1200T HTTP POST Request formSysCmd buffer overflow
Published 2025-06-16 · Analyzed
9.0EPSS 0.010
CVE-2025-6145
TOTOLINK EX1200T HTTP POST Request formSysLog buffer overflow
Published 2025-06-16 · Analyzed
9.0EPSS 0.010
CVE-2025-6162
TOTOLINK EX1200T HTTP POST Request formMultiAP buffer overflow
Published 2025-06-17 · Analyzed
9.0EPSS 0.010
CVE-2025-6130
TOTOLINK EX1200T HTTP POST Request formStats buffer overflow
Published 2025-06-16 · Analyzed
9.0EPSS 0.010
CVE-2025-6143
TOTOLINK EX1200T HTTP POST Request formNtp buffer overflow
Published 2025-06-16 · Analyzed
9.0EPSS 0.010
CVE-2025-6302
TOTOLINK EX1200T cstecgi.cgi setStaticDhcpConfig stack-based overflow
Published 2025-06-20 · Analyzed
9.0EPSS 0.010
CVE-2025-6568
TOTOLINK EX1200T HTTP POST Request formIpv6Setup buffer overflow
Published 2025-06-24 · Analyzed
9.0EPSS 0.009
CVE-2025-6129
TOTOLINK EX1200T HTTP POST Request formSaveConfig buffer overflow
Published 2025-06-16 · Analyzed
9.0EPSS 0.009
CVE-2025-6336
TOTOLINK EX1200T HTTP POST Request formTmultiAP buffer overflow
Published 2025-06-20 · Analyzed
9.0EPSS 0.009
CVE-2025-5793
TOTOLINK EX1200T HTTP POST Request formPortFw buffer overflow
Published 2025-06-06 · Analyzed
9.0EPSS 0.009
CVE-2022-25008
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
Published 2022-03-30 · Modified
8.8EPSS 0.044
CVE-2021-42877
TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.
Published 2022-06-02 · Modified
7.8EPSS 0.017
CVE-2021-42886
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file.
Published 2022-06-03 · Modified
7.5EPSS 0.021
CVE-2021-42893
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.
Published 2022-06-03 · Modified
7.5EPSS 0.014
CVE-2021-42891
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
Published 2022-06-03 · Modified
7.5EPSS 0.014
CVE-2021-42889
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.
Published 2022-06-03 · Modified
7.5EPSS 0.014
CVE-2021-42892
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.
Published 2022-06-03 · Modified
5.0EPSS 0.007