VendorsTOTOLINKex1800tall versions
Vulnerabilities

TOTOLINK EX1800T

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2025-2094
TOTOLINK EX1800T cstecgi.cgi setWiFiExtenderConfig os command injection
Published 2025-03-07 · Analyzed
9.8EPSS 0.130
CVE-2025-2097
TOTOLINK EX1800T cstecgi.cgi setRptWizardCfg stack-based overflow
Published 2025-03-07 · Analyzed
9.8EPSS 0.072
CVE-2024-34257
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.
Published 2024-05-08 · Analyzed
9.8EPSS 0.038
CVE-2025-2096
TOTOLINK EX1800T cstecgi.cgi setRebootScheCfg os command injection
Published 2025-03-07 · Analyzed
9.8EPSS 0.027
CVE-2025-2095
TOTOLINK EX1800T cstecgi.cgi setDmzCfg os command injection
Published 2025-03-07 · Analyzed
9.8EPSS 0.027
CVE-2023-52026
TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface
Published 2024-01-12 · Modified
9.8EPSS 0.016
CVE-2025-2370
TOTOLINK EX1800T cstecgi.cgi setWiFiExtenderConfig stack-based overflow
Published 2025-03-17 · Analyzed
9.8EPSS 0.011
CVE-2025-2369
TOTOLINK EX1800T cstecgi.cgi setPasswordCfg stack-based overflow
Published 2025-03-17 · Analyzed
9.8EPSS 0.011
CVE-2023-51025
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51028
TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtenderConfig interface of the cstecgi.cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51026
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51014
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51015
TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51016
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51018
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51023
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘host_time’ parameter of the NTPSyncWithHost interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51012
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanGateway parameter’ of the setLanConfig interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51013
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanNetmask parameter’ of the setLanConfig interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51017
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51019
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘key5g’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51020
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langType’ parameter of the setLanguageCfg interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51027
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘apcliAuthMode’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51021
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51011
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanPriDns parameter’ of the setLanConfig interface of the cstecgi .cgi
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51024
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘tz’ parameter of the setNtpCfg interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2023-51022
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.
Published 2023-12-22 · Modified
9.8EPSS 0.010
CVE-2025-1852
Totolink EX1800T cstecgi.cgi loginAuth buffer overflow
Published 2025-03-03 · Analyzed
9.8EPSS 0.009
CVE-2024-12352
TOTOLINK EX1800T cstecgi.cgi sub_40662C stack-based overflow
Published 2024-12-09 · Analyzed
9.8EPSS 0.008