VendorsTOTOLINKn600r_firmwareall versions
Vulnerabilities

TOTOLINK N600R Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

38CVEs
CVE-2022-28906
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.
Published 2022-05-10 · Modified
10.0EPSS 0.029
CVE-2022-28913
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUploadSetting.
Published 2022-05-10 · Modified
10.0EPSS 0.026
CVE-2022-28912
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW.
Published 2022-05-10 · Modified
10.0EPSS 0.026
CVE-2022-28905
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parameter in /setting/setDeviceName.
Published 2022-05-10 · Modified
10.0EPSS 0.026
CVE-2022-28907
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.
Published 2022-05-10 · Modified
10.0EPSS 0.026
CVE-2022-28908
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in /setting/setDiagnosisCfg.
Published 2022-05-10 · Modified
10.0EPSS 0.026
CVE-2022-28909
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx parameter in /setting/setWebWlanIdx.
Published 2022-05-10 · Modified
10.0EPSS 0.026
CVE-2022-28910
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicename parameter in /setting/setDeviceName.
Published 2022-05-10 · Modified
10.0EPSS 0.026
CVE-2022-28911
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/CloudACMunualUpdate.
Published 2022-05-10 · Modified
10.0EPSS 0.026
CVE-2022-27411
TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Main" function.
Published 2022-05-05 · Modified
10.0EPSS 0.025
CVE-2022-29399
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the url parameter in the function FUN_00415bf0.
Published 2022-05-10 · Modified
10.0EPSS 0.017
CVE-2022-29398
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the File parameter in the function FUN_0041309c.
Published 2022-05-10 · Modified
10.0EPSS 0.017
CVE-2022-29397
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004196c8.
Published 2022-05-10 · Modified
10.0EPSS 0.017
CVE-2022-29396
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418f10.
Published 2022-05-10 · Modified
10.0EPSS 0.017
CVE-2022-29395
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the apcliKey parameter in the function FUN_0041bac4.
Published 2022-05-10 · Modified
10.0EPSS 0.017
CVE-2022-29394
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macAddress parameter in the function FUN_0041b448.
Published 2022-05-10 · Modified
10.0EPSS 0.017
CVE-2022-29393
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004192cc.
Published 2022-05-10 · Modified
10.0EPSS 0.017
CVE-2022-29392
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418c24.
Published 2022-05-10 · Modified
10.0EPSS 0.017
CVE-2022-29391
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004200c8.
Published 2022-05-10 · Modified
10.0EPSS 0.017
CVE-2022-26187
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.
Published 2022-03-22 · Modified
9.8EPSS 0.196
CVE-2022-26186
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.
Published 2022-03-22 · Modified
9.8EPSS 0.039
CVE-2022-26189
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.
Published 2022-03-22 · Modified
9.8EPSS 0.034
CVE-2022-26188
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.
Published 2022-03-22 · Modified
9.8EPSS 0.034
CVE-2025-9935
TOTOLINK N600R cstecgi.cgi sub_4159F8 command injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.030
CVE-2025-51390
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.
Published 2025-08-04 · Modified
9.8EPSS 0.018
CVE-2025-4496
TOTOLINK T10/A3100R/A950RG/A800R/N600R/A3000RU/A810R cstecgi.cgi CloudACMunualUpdate buffer overflow
Published 2025-05-10 · Analyzed
9.8EPSS 0.012
CVE-2025-46060
Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILENAME component
Published 2025-06-13 · Modified
9.8EPSS 0.010
CVE-2023-43141
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
Published 2023-09-25 · Modified
9.8EPSS 0.007
CVE-2025-22900
Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.
Published 2025-04-15 · Analyzed
9.8EPSS 0.006
CVE-2025-11444
TOTOLINK N600R HTTP Request cstecgi.cgi setWiFiBasicConfig buffer overflow
Published 2025-10-08 · Analyzed
9.0EPSS 0.010
CVE-2025-8181
TOTOLINK N600R/X2000R FTP Service vsftpd.conf least privilege violation
Published 2025-07-26 · Analyzed
8.6EPSS 0.009
CVE-2022-36613
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Published 2022-08-28 · Modified
7.8EPSS 0.003
CVE-2025-60335
A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published 2025-10-22 · Analyzed
7.5EPSS 0.021
CVE-2025-60336
A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published 2025-10-22 · Analyzed
7.5EPSS 0.018
CVE-2025-60334
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Analyzed
7.5EPSS 0.006
CVE-2025-60333
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Analyzed
7.5EPSS 0.005
CVE-2025-57623
A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.
Published 2025-09-25 · Analyzed
5.3EPSS 0.004
CVE-2025-22903
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.
Published 2025-04-15 · Analyzed
4.6EPSS 0.002