VendorsTOTOLINKn350rt_firmware9.3.5u.6139_b20201216
Vulnerabilities

TOTOLINK n350rt Firmware 9.3.5u.6139_b20201216

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2024-7462
TOTOLINK N350RT cstecgi.cgi setWizardCfg buffer overflow
Published 2024-08-05 · Analyzed
9.8EPSS 0.013
CVE-2023-7219
Totolink N350RT cstecgi.cgi loginAuth stack-based overflow
Published 2024-01-09 · Modified
9.8EPSS 0.013
CVE-2024-42966
Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
Published 2024-08-15 · Modified
9.8EPSS 0.006
CVE-2025-51630
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the function setIpPortFilterRules.
Published 2025-07-17 · Analyzed
9.8EPSS 0.005
CVE-2024-7333
TOTOLINK N350RT cstecgi.cgi setParentalRules buffer overflow
Published 2024-08-01 · Analyzed
9.0EPSS 0.012
CVE-2023-7213
Totolink N350RT HTTP POST Request main stack-based overflow
Published 2024-01-07 · Modified
8.8EPSS 0.009
CVE-2023-7214
Totolink N350RT HTTP POST Request main stack-based overflow
Published 2024-01-07 · Modified
8.8EPSS 0.009
CVE-2023-7187
Totolink N350RT HTTP POST Request stack-based overflow
Published 2023-12-31 · Modified
8.8EPSS 0.007
CVE-2023-7218
Totolink N350RT cstecgi.cgi loginAuth stack-based overflow
Published 2024-01-08 · Modified
8.3EPSS 0.013
CVE-2022-36481
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.013
CVE-2022-36485
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.011
CVE-2022-36486
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
Published 2022-08-25 · Modified
7.8EPSS 0.011
CVE-2022-36487
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.011
CVE-2022-36479
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.
Published 2022-08-25 · Modified
7.8EPSS 0.011
CVE-2022-36482
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the lang parameter in the function setLanguageCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.009
CVE-2022-36488
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.
Published 2022-08-25 · Modified
7.8EPSS 0.003
CVE-2022-36484
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the function setDiagnosisCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.003
CVE-2022-36483
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the pppoeUser parameter.
Published 2022-08-25 · Modified
7.8EPSS 0.003
CVE-2022-36480
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.003