VendorsTOTOLINKt8any version
Vulnerabilities

TOTOLINK T8 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2024-8077
TOTOLINK AC1200 T8 setTracerouteCfg os command injection
Published 2024-08-22 · Analyzed
9.8EPSS 0.029
CVE-2023-24151
A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2023-02-03 · Modified
9.8EPSS 0.021
CVE-2023-24152
A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2023-02-03 · Modified
9.8EPSS 0.021
CVE-2023-24153
A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2023-02-03 · Modified
9.8EPSS 0.021
CVE-2023-24156
A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2023-02-03 · Modified
9.8EPSS 0.021
CVE-2023-24157
A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2023-02-03 · Modified
9.8EPSS 0.021
CVE-2023-24150
A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Published 2023-02-03 · Modified
9.8EPSS 0.021
CVE-2023-24154
TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2024-8075
TOTOLINK AC1200 T8 setDiagnosisCfg os command injection
Published 2024-08-22 · Analyzed
9.8EPSS 0.019
CVE-2024-8579
TOTOLINK AC1200 T8 cstecgi.cgi setWiFiRepeaterCfg buffer overflow
Published 2024-09-08 · Analyzed
9.8EPSS 0.013
CVE-2024-46451
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.
Published 2024-09-16 · Modified
9.8EPSS 0.012
CVE-2024-8079
TOTOLINK AC1200 T8 exportOvpn buffer overflow
Published 2024-08-22 · Analyzed
9.8EPSS 0.011
CVE-2024-8078
TOTOLINK AC1200 T8 setTracerouteCfg buffer overflow
Published 2024-08-22 · Analyzed
9.8EPSS 0.010
CVE-2023-24155
TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.
Published 2023-02-03 · Modified
9.8EPSS 0.009
CVE-2024-8076
TOTOLINK AC1200 T8 setDiagnosisCfg buffer overflow
Published 2024-08-22 · Analyzed
9.8EPSS 0.008
CVE-2024-46419
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.
Published 2024-09-16 · Modified
9.8EPSS 0.007
CVE-2024-8580
TOTOLINK AC1200 T8 shadow.sample hard-coded password
Published 2024-09-08 · Analyzed
9.2EPSS 0.013
CVE-2024-0569
Totolink T8 Setting cstecgi.cgi getSysStatusCfg information disclosure
Published 2024-01-16 · Modified
9.1EPSS 0.010
CVE-2024-8573
TOTOLINK AC1200 T8/AC1200 T10 cstecgi.cgi setParentalRules buffer overflow
Published 2024-09-08 · Modified
9.0EPSS 0.014
CVE-2024-8575
TOTOLINK AC1200 T8 cstecgi.cgi setWiFiScheduleCfg buffer overflow
Published 2024-09-08 · Analyzed
9.0EPSS 0.011
CVE-2024-8576
TOTOLINK AC1200 T8/AC1200 T10 cstecgi.cgi setIpPortFilterRules buffer overflow
Published 2024-09-08 · Analyzed
9.0EPSS 0.011
CVE-2024-8577
TOTOLINK AC1200 T8/AC1200 T10 cstecgi.cgi setStaticDhcpRules buffer overflow
Published 2024-09-08 · Analyzed
9.0EPSS 0.011
CVE-2024-8578
TOTOLINK AC1200 T8 cstecgi.cgi setWiFiMeshName buffer overflow
Published 2024-09-08 · Analyzed
9.0EPSS 0.011
CVE-2024-8574
TOTOLINK AC1200 T8 cstecgi.cgi setParentalRules os command injection
Published 2024-09-08 · Analyzed
8.8EPSS 0.031
CVE-2024-46424
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.
Published 2024-09-16 · Modified
7.5EPSS 0.006
CVE-2024-0944
Totolink T8 cstecgi.cgi session expiration
Published 2024-01-26 · Modified
5.3EPSS 0.015