VendorsTOTOLINKx2000rany version
Vulnerabilities

TOTOLINK X2000R any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

42CVEs
CVE-2024-0579
Totolink X2000R formMapDelDevice command injection
Published 2024-01-16 · Modified
9.8EPSS 0.022
CVE-2023-7222
Totolink X2000R HTTP POST Request boa formTmultiAP buffer overflow
Published 2024-01-09 · Modified
9.8EPSS 0.013
CVE-2023-46547
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSysLog.
Published 2023-10-25 · Modified
9.8EPSS 0.010
CVE-2023-46545
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWsc.
Published 2023-10-25 · Modified
9.8EPSS 0.010
CVE-2023-46546
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formStats.
Published 2023-10-25 · Modified
9.8EPSS 0.010
CVE-2023-46541
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpv6Setup.
Published 2023-10-25 · Modified
9.8EPSS 0.010
CVE-2023-46544
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWirelessTbl.
Published 2023-10-25 · Modified
9.8EPSS 0.010
CVE-2023-46542
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMeshUploadConfig.
Published 2023-10-25 · Modified
9.8EPSS 0.010
CVE-2023-46540
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formNtp.
Published 2023-10-25 · Modified
9.8EPSS 0.010
CVE-2023-46543
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlSiteSurvey.
Published 2023-10-25 · Modified
9.8EPSS 0.010
CVE-2023-46556
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formFilter.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46555
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPortFw.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46548
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlanRedirect.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46558
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46557
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAPVLAN.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46549
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSetLg.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46550
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDelDevice.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46551
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formReflashClientTbl.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46554
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMapDel.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46560
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46559
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46563
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46562
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46564
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46552
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAP.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-46553
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formParentControl.
Published 2023-10-25 · Modified
9.8EPSS 0.008
CVE-2023-51133
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRoute.
Published 2023-12-30 · Modified
9.8EPSS 0.006
CVE-2023-51135
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPasswordSetup.
Published 2023-12-30 · Modified
9.8EPSS 0.006
CVE-2023-51136
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSchedule.
Published 2023-12-30 · Modified
9.8EPSS 0.006
CVE-2025-8181
TOTOLINK N600R/X2000R FTP Service vsftpd.conf least privilege violation
Published 2025-07-26 · Analyzed
8.6EPSS 0.009
CVE-2024-28404
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.
Published 2024-03-15 · Analyzed
8.0EPSS 0.005
CVE-2025-9577
TOTOLINK X2000R Administrative shadow.sample default credentials
Published 2025-08-28 · Analyzed
7.0EPSS 0.002
CVE-2025-5504
TOTOLINK X2000R formWsc command injection
Published 2025-06-03 · Analyzed
6.5EPSS 0.129
CVE-2025-5515
TOTOLINK X2000R formMapDel command injection
Published 2025-06-03 · Analyzed
6.5EPSS 0.032
CVE-2024-28402
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
Published 2024-03-21 · Analyzed
5.9EPSS 0.004
CVE-2024-28403
TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.
Published 2024-03-15 · Modified
5.4EPSS 0.004
CVE-2024-29419
There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.
Published 2024-03-20 · Modified
5.4EPSS 0.004
CVE-2024-28401
TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.
Published 2024-03-15 · Modified
5.4EPSS 0.004
CVE-2024-33433
Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.
Published 2024-05-13 · Analyzed
4.8EPSS 0.006
CVE-2025-5516
TOTOLINK X2000R URL Filtering Page formFilter cross site scripting
Published 2025-06-03 · Analyzed
4.8EPSS 0.004
1 / 2Next →