VendorsTOTOLINKn600r_firmware4.3.0cu.7866_b20220506
Vulnerabilities

TOTOLINK N600R Firmware 4.3.0cu.7866_b20220506

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-9935
TOTOLINK N600R cstecgi.cgi sub_4159F8 command injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.030
CVE-2025-60335
A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published 2025-10-22 · Analyzed
7.5EPSS 0.021
CVE-2025-60336
A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published 2025-10-22 · Analyzed
7.5EPSS 0.018
CVE-2025-60334
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Analyzed
7.5EPSS 0.006
CVE-2025-60333
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Analyzed
7.5EPSS 0.005