VendorsTOTOLINKnr1800xall versions
Vulnerabilities

TOTOLINK NR1800X

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2023-7220
Totolink NR1800X cstecgi.cgi loginAuth stack-based overflow
Published 2024-01-09 · Modified
10.0EPSS 0.015
CVE-2026-5030
Totolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection
Published 2026-03-29 · Analyzed
9.8EPSS 0.025
CVE-2022-41518
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
Published 2022-10-06 · Modified
9.8EPSS 0.019
CVE-2022-41525
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.
Published 2022-10-06 · Modified
9.8EPSS 0.018
CVE-2022-41522
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.
Published 2022-10-06 · Modified
9.8EPSS 0.010
CVE-2023-36340
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
Published 2023-10-16 · Modified
9.8EPSS 0.007
CVE-2025-45841
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
Published 2025-05-08 · Analyzed
9.8EPSS 0.005
CVE-2026-1328
Totolink NR1800X POST Request cstecgi.cgi setWizardCfg buffer overflow
Published 2026-01-22 · Analyzed
9.0EPSS 0.009
CVE-2026-1326
Totolink NR1800X POST Request cstecgi.cgi setWanCfg command injection
Published 2026-01-22 · Analyzed
8.8EPSS 0.035
CVE-2026-1327
Totolink NR1800X POST Request cstecgi.cgi setTracerouteCfg command injection
Published 2026-01-22 · Analyzed
8.8EPSS 0.029
CVE-2024-35388
TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode
Published 2024-05-24 · Analyzed
8.8EPSS 0.025
CVE-2022-44256
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.
Published 2022-11-23 · Modified
8.8EPSS 0.022
CVE-2022-41521
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41528
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41527
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41526
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41524
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41523
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41520
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41517
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2025-45842
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.
Published 2025-05-08 · Analyzed
8.8EPSS 0.009
CVE-2025-45843
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.
Published 2025-05-08 · Analyzed
8.8EPSS 0.007
CVE-2025-45844
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.
Published 2025-05-08 · Analyzed
8.8EPSS 0.007
CVE-2025-45845
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function.
Published 2025-05-08 · Analyzed
8.8EPSS 0.007
CVE-2025-60684
A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings using sprintf() into fixed-size stack buffers without proper length validation. Maliciously crafted input can overflow these buffers, potentially leading to arbitrary code execution or memory corruption, without requiring authentication.
Published 2025-11-13 · Modified
6.5EPSS 0.005
CVE-2025-60688
A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads the "IpAddress" parameter from a web request and copies it into a fixed-size stack buffer using strcpy() without any length validation. Maliciously crafted input can overflow the buffer, leading to potential arbitrary code execution or memory corruption, without requiring authentication.
Published 2025-11-13 · Modified
6.5EPSS 0.005
CVE-2025-60686
A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using sscanf() with "%s" format specifiers into fixed-size stack buffers without length validation. Specifically, one function writes user-controlled data into a single-byte buffer, and the other into adjacent small arrays without bounds checking. An attacker who controls the contents of /proc/net/arp can trigger memory corruption, leading to denial of service or potential arbitrary code execution.
Published 2025-11-13 · Modified
5.1EPSS 0.002