VendorsTOTOLINKnr1800x_firmware9.1.0u.6279_b20210910
Vulnerabilities

TOTOLINK NR1800X Firmware 9.1.0u.6279_b20210910

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2023-7220
Totolink NR1800X cstecgi.cgi loginAuth stack-based overflow
Published 2024-01-09 · Modified
10.0EPSS 0.015
CVE-2026-5030
Totolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection
Published 2026-03-29 · Analyzed
9.8EPSS 0.037
CVE-2022-41518
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
Published 2022-10-06 · Modified
9.8EPSS 0.019
CVE-2022-41525
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.
Published 2022-10-06 · Modified
9.8EPSS 0.018
CVE-2022-41522
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.
Published 2022-10-06 · Modified
9.8EPSS 0.010
CVE-2023-36340
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
Published 2023-10-16 · Modified
9.8EPSS 0.007
CVE-2026-1328
Totolink NR1800X POST Request cstecgi.cgi setWizardCfg buffer overflow
Published 2026-01-22 · Analyzed
9.0EPSS 0.009
CVE-2026-1326
Totolink NR1800X POST Request cstecgi.cgi setWanCfg command injection
Published 2026-01-22 · Analyzed
8.8EPSS 0.035
CVE-2026-1327
Totolink NR1800X POST Request cstecgi.cgi setTracerouteCfg command injection
Published 2026-01-22 · Analyzed
8.8EPSS 0.029
CVE-2022-41521
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilterRules function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41523
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41524
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the setParentalRules function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41526
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41527
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41528
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41520
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
Published 2022-10-06 · Modified
8.8EPSS 0.009
CVE-2022-41517
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function
Published 2022-10-06 · Modified
8.8EPSS 0.009