VendorsTOTOLINKlr1200gball versions
Vulnerabilities

TOTOLINK LR1200GB

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2024-1783
Totolink LR1200GB Web Interface cstecgi.cgi loginAuth stack-based overflow
Published 2024-02-23 · Analyzed
10.0EPSS 0.020
CVE-2023-46977
TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.
Published 2023-10-31 · Modified
9.8EPSS 0.087
CVE-2024-0292
Totolink LR1200GB cstecgi.cgi setOpModeCfg os command injection
Published 2024-01-08 · Modified
9.8EPSS 0.049
CVE-2024-0293
Totolink LR1200GB cstecgi.cgi setUploadSetting os command injection
Published 2024-01-08 · Modified
9.8EPSS 0.048
CVE-2024-0294
Totolink LR1200GB cstecgi.cgi setUssd os command injection
Published 2024-01-08 · Modified
9.8EPSS 0.038
CVE-2024-0295
Totolink LR1200GB cstecgi.cgi setWanCfg os command injection
Published 2024-01-08 · Modified
9.8EPSS 0.038
CVE-2024-0571
Totolink LR1200GB cstecgi.cgi setSmsCfg stack-based overflow
Published 2024-01-16 · Modified
9.8EPSS 0.013
CVE-2024-0572
Totolink LR1200GB cstecgi.cgi setOpModeCfg stack-based overflow
Published 2024-01-16 · Modified
9.8EPSS 0.013
CVE-2024-0574
Totolink LR1200GB cstecgi.cgi setParentalRules stack-based overflow
Published 2024-01-16 · Modified
9.8EPSS 0.011
CVE-2024-0575
Totolink LR1200GB cstecgi.cgi setTracerouteCfg stack-based overflow
Published 2024-01-16 · Modified
9.8EPSS 0.011
CVE-2024-0573
Totolink LR1200GB cstecgi.cgi setDiagnosisCfg stack-based overflow
Published 2024-01-16 · Modified
9.8EPSS 0.011
CVE-2024-0578
Totolink LR1200GB cstecgi.cgi UploadCustomModule stack-based overflow
Published 2024-01-16 · Modified
9.8EPSS 0.011
CVE-2024-0576
Totolink LR1200GB cstecgi.cgi setIpPortFilterRules stack-based overflow
Published 2024-01-16 · Modified
9.8EPSS 0.010
CVE-2024-0577
Totolink LR1200GB cstecgi.cgi setLanguageCfg stack-based overflow
Published 2024-01-16 · Modified
9.8EPSS 0.010
CVE-2024-0291
Totolink LR1200GB cstecgi.cgi UploadFirmwareFile command injection
Published 2024-01-08 · Modified
8.8EPSS 0.044
CVE-2025-60687
An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi binary (sub_41EC68 function). The binary reads the "imei" parameter from a web request and verifies only that it is 15 characters long. The parameter is then directly inserted into a system command using sprintf() and executed with system(). Maliciously crafted IMEI input can execute arbitrary commands on the router without authentication.
Published 2025-11-13 · Modified
6.5EPSS 0.066
CVE-2025-60684
A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings using sprintf() into fixed-size stack buffers without proper length validation. Maliciously crafted input can overflow these buffers, potentially leading to arbitrary code execution or memory corruption, without requiring authentication.
Published 2025-11-13 · Modified
6.5EPSS 0.005
CVE-2025-60688
A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads the "IpAddress" parameter from a web request and copies it into a fixed-size stack buffer using strcpy() without any length validation. Maliciously crafted input can overflow the buffer, leading to potential arbitrary code execution or memory corruption, without requiring authentication.
Published 2025-11-13 · Modified
6.5EPSS 0.005
CVE-2025-60686
A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using sscanf() with "%s" format specifiers into fixed-size stack buffers without length validation. Specifically, one function writes user-controlled data into a single-byte buffer, and the other into adjacent small arrays without bounds checking. An attacker who controls the contents of /proc/net/arp can trigger memory corruption, leading to denial of service or potential arbitrary code execution.
Published 2025-11-13 · Modified
5.1EPSS 0.002