VendorsTOTOLINKex200_firmware4.0.3c.7646_b20201211
Vulnerabilities

TOTOLINK Ex200 Firmware 4.0.3c.7646 B20201211 4.0.3c.7646_b20201211

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2021-43711
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.
Published 2022-01-04 · Modified
9.8EPSS 0.378
CVE-2024-31807
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.
Published 2024-04-08 · Analyzed
9.8EPSS 0.014
CVE-2024-31810
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Published 2024-05-13 · Analyzed
9.8EPSS 0.006
CVE-2024-31815
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
Published 2024-04-08 · Analyzed
9.1EPSS 0.006
CVE-2024-7336
TOTOLINK EX200 cstecgi.cgi loginauth buffer overflow
Published 2024-08-01 · Analyzed
9.0EPSS 0.013
CVE-2024-7335
TOTOLINK EX200 getSaveConfig buffer overflow
Published 2024-08-01 · Analyzed
9.0EPSS 0.012
CVE-2024-31814
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.
Published 2024-04-08 · Analyzed
8.8EPSS 0.083
CVE-2024-31809
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.
Published 2024-04-08 · Analyzed
8.8EPSS 0.010
CVE-2024-31808
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
Published 2024-04-08 · Analyzed
8.8EPSS 0.009
CVE-2024-31813
TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.
Published 2024-04-08 · Analyzed
8.4EPSS 0.002
CVE-2024-31811
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.
Published 2024-04-08 · Analyzed
8.0EPSS 0.010
CVE-2024-31817
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
Published 2024-04-08 · Analyzed
7.5EPSS 0.553
CVE-2024-31816
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.
Published 2024-04-08 · Analyzed
7.5EPSS 0.027
CVE-2024-32326
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.
Published 2024-04-18 · Analyzed
6.8EPSS 0.006
CVE-2024-31805
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.
Published 2024-04-08 · Analyzed
6.5EPSS 0.005
CVE-2024-31806
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.
Published 2024-04-08 · Analyzed
6.5EPSS 0.004
CVE-2024-31812
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.
Published 2024-04-08 · Analyzed
6.5EPSS 0.003
CVE-2024-53333
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.
Published 2024-11-21 · Analyzed
6.3EPSS 0.194
CVE-2024-32325
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.
Published 2024-04-18 · Analyzed
2.4EPSS 0.005