VendorsTOTOLINKn200re_firmwareall versions
Vulnerabilities

TOTOLINK N200re Firmware -

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2019-19825
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The attacker can perform router actions via HTTP requests with Basic Authentication.) This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.
Published 2020-01-27 · Modified
9.8EPSS 0.296
CVE-2024-0296
Totolink N200RE cstecgi.cgi NTPSyncWithHost os command injection
Published 2024-01-08 · Modified
9.8EPSS 0.038
CVE-2024-0297
Totolink N200RE cstecgi.cgi UploadFirmwareFile os command injection
Published 2024-01-08 · Modified
9.8EPSS 0.038
CVE-2024-0298
Totolink N200RE cstecgi.cgi setDiagnosisCfg os command injection
Published 2024-01-08 · Modified
9.8EPSS 0.038
CVE-2024-0299
Totolink N200RE cstecgi.cgi setTracerouteCfg os command injection
Published 2024-01-08 · Modified
9.8EPSS 0.038
CVE-2024-1001
Totolink N200RE cstecgi.cgi main stack-based overflow
Published 2024-01-29 · Modified
9.8EPSS 0.014
CVE-2025-55895
TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).
Published 2025-12-15 · Analyzed
9.1EPSS 0.003
CVE-2019-19824
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.
Published 2020-01-27 · Modified
9.0EPSS 0.251
CVE-2025-7154
TOTOLINK N200RE cstecgi.cgi sub_41A0F8 os command injection
Published 2025-07-08 · Analyzed
8.8EPSS 0.024
CVE-2024-0999
Totolink N200RE cstecgi.cgi setParentalRules stack-based overflow
Published 2024-01-29 · Modified
8.8EPSS 0.015
CVE-2024-0998
Totolink N200RE cstecgi.cgi setDiagnosisCfg stack-based overflow
Published 2024-01-29 · Modified
8.8EPSS 0.014
CVE-2024-0997
Totolink N200RE cstecgi.cgi setOpModeCfg stack-based overflow
Published 2024-01-29 · Modified
8.8EPSS 0.013
CVE-2024-1003
Totolink N200RE cstecgi.cgi setLanguageCfg stack-based overflow
Published 2024-01-29 · Modified
8.8EPSS 0.013
CVE-2024-1002
Totolink N200RE cstecgi.cgi setIpPortFilterRules stack-based overflow
Published 2024-01-29 · Modified
8.8EPSS 0.013
CVE-2024-1000
Totolink N200RE cstecgi.cgi setTracerouteCfg stack-based overflow
Published 2024-01-29 · Modified
8.8EPSS 0.013
CVE-2024-1004
Totolink N200RE cstecgi.cgi loginAuth stack-based overflow
Published 2024-01-29 · Modified
8.3EPSS 0.013
CVE-2019-19822
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
Published 2020-01-27 · Modified
7.5EPSS 0.087
CVE-2019-19823
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
Published 2020-01-27 · Modified
7.5EPSS 0.064
CVE-2025-55893
TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.
Published 2025-12-15 · Analyzed
6.5EPSS 0.011
CVE-2020-23617
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
Published 2022-05-02 · Modified
6.1EPSS 0.006
CVE-2023-2790
TOTOLINK N200RE Telnet Service custom.conf password in configuration file
Published 2023-05-18 · Modified
5.5EPSS 0.003