VendorsTOTOLINKlr350all versions
Vulnerabilities

TOTOLINK LR350

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2024-35387
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
Published 2024-05-24 · Analyzed
9.8EPSS 0.061
CVE-2022-44255
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.
Published 2022-11-23 · Modified
9.8EPSS 0.023
CVE-2023-37149
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
Published 2023-07-07 · Modified
9.8EPSS 0.020
CVE-2023-37148
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
Published 2023-07-07 · Modified
9.8EPSS 0.020
CVE-2023-37146
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
Published 2023-07-07 · Modified
9.8EPSS 0.020
CVE-2023-37145
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
Published 2023-07-07 · Modified
9.8EPSS 0.020
CVE-2022-44250
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.
Published 2022-11-23 · Modified
9.8EPSS 0.018
CVE-2022-44252
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
Published 2022-11-23 · Modified
9.8EPSS 0.018
CVE-2022-44251
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
Published 2022-11-23 · Modified
9.8EPSS 0.018
CVE-2022-44249
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.
Published 2022-11-23 · Modified
9.8EPSS 0.018
CVE-2024-36783
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.
Published 2024-06-03 · Analyzed
9.8EPSS 0.014
CVE-2024-35099
TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.
Published 2024-05-13 · Analyzed
9.8EPSS 0.008
CVE-2024-42967
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
Published 2024-08-15 · Modified
9.8EPSS 0.006
CVE-2024-10654
TOTOLINK LR350 formLoginAuth.htm authorization
Published 2024-11-01 · Analyzed
9.1EPSS 0.016
CVE-2026-1157
Totolink LR350 cstecgi.cgi setWiFiEasyCfg buffer overflow
Published 2026-01-19 · Analyzed
9.0EPSS 0.010
CVE-2026-1155
Totolink LR350 cstecgi.cgi setWiFiEasyGuestCfg buffer overflow
Published 2026-01-19 · Analyzed
9.0EPSS 0.009
CVE-2026-1158
Totolink LR350 POST Request cstecgi.cgi setWizardCfg buffer overflow
Published 2026-01-19 · Analyzed
9.0EPSS 0.007
CVE-2026-1156
Totolink LR350 cstecgi.cgi setWiFiBasicCfg buffer overflow
Published 2026-01-19 · Analyzed
9.0EPSS 0.007
CVE-2026-4976
Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow
Published 2026-03-27 · Analyzed
9.0EPSS 0.007
CVE-2024-7214
TOTOLINK LR350 cstecgi.cgi setWanCfg command injection
Published 2024-07-30 · Modified
8.8EPSS 0.032
CVE-2026-1149
Totolink LR350 POST Request cstecgi.cgi setDiagnosisCfg command injection
Published 2026-01-19 · Analyzed
8.8EPSS 0.031
CVE-2026-1150
Totolink LR350 POST Request cstecgi.cgi setTracerouteCfg command injection
Published 2026-01-19 · Analyzed
8.8EPSS 0.027
CVE-2022-44258
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.
Published 2022-11-23 · Modified
8.8EPSS 0.024
CVE-2022-44257
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.
Published 2022-11-23 · Modified
8.8EPSS 0.022
CVE-2022-44253
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.
Published 2022-11-23 · Modified
8.8EPSS 0.022
CVE-2022-44254
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.
Published 2022-11-23 · Modified
8.8EPSS 0.022
CVE-2022-44260
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.
Published 2022-11-23 · Modified
8.8EPSS 0.022
CVE-2022-44259
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.
Published 2022-11-23 · Modified
8.8EPSS 0.022
CVE-2024-34308
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.
Published 2024-05-08 · Analyzed
8.8EPSS 0.006
CVE-2025-63463
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-10-31 · Analyzed
7.5EPSS 0.004
CVE-2025-63464
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-10-31 · Analyzed
7.5EPSS 0.004
CVE-2025-63465
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-10-31 · Analyzed
7.5EPSS 0.004
CVE-2025-63466
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-10-31 · Analyzed
7.5EPSS 0.004
CVE-2025-63467
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-10-31 · Analyzed
7.5EPSS 0.004
CVE-2025-63468
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-10-31 · Analyzed
7.5EPSS 0.004
CVE-2025-63469
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-10-31 · Analyzed
7.5EPSS 0.004