VendorsTOTOLINKx5000r_firmware9.1.0cu.2350_b20230313
Vulnerabilities

TOTOLINK X5000r Firmware 9.1.0u.6118 B20201102 9.1.0cu.2350_b20230313

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2023-31569
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
Published 2023-06-06 · Modified
9.8EPSS 0.031
CVE-2024-32353
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
Published 2024-05-14 · Analyzed
9.8EPSS 0.021
CVE-2023-39617
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
Published 2023-08-21 · Modified
9.8EPSS 0.017
CVE-2024-34921
TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.
Published 2024-05-13 · Analyzed
8.8EPSS 0.092
CVE-2024-32350
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.
Published 2024-05-14 · Analyzed
8.8EPSS 0.022
CVE-2024-32351
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.
Published 2024-05-14 · Analyzed
8.8EPSS 0.022
CVE-2024-32352
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.
Published 2024-05-14 · Analyzed
8.8EPSS 0.022
CVE-2024-57011
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.017
CVE-2024-57012
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57022
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57021
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57020
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiScheduleCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57019
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57018
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57017
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57016
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57015
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57013
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.016
CVE-2024-57014
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg.
Published 2025-01-15 · Modified
8.8EPSS 0.012
CVE-2024-32355
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.
Published 2024-05-14 · Analyzed
8.0EPSS 0.018
CVE-2024-42736
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
Published 2024-08-13 · Analyzed
7.8EPSS 0.016
CVE-2024-42740
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
Published 2024-08-13 · Analyzed
6.8EPSS 0.027
CVE-2024-57024
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.
Published 2025-01-15 · Analyzed
6.8EPSS 0.015
CVE-2024-57023
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.
Published 2025-01-15 · Analyzed
6.8EPSS 0.014
CVE-2024-57025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg.
Published 2025-01-15 · Analyzed
6.8EPSS 0.014
CVE-2024-32354
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
Published 2024-05-14 · Analyzed
6.0EPSS 0.010
CVE-2024-32349
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.
Published 2024-05-14 · Analyzed
6.0EPSS 0.009