Totolink
Totolink Ex1200t Firmware: vulnerabilidades y CVE
Totolink Ex1200t Firmware tiene 37 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE37
Últimos 12 meses0
Críticas12
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-51451 | Crítica (9.8) | 0.38% | — | 13 ago 2025 | In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. |
| CVE-2025-6568 | Alta (7.4) | 1.00% | — | 24 jun 2025 | A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formIpv6Setup of the component HTTP POST Request Handler. The… |
| CVE-2025-6393 | Alta (7.4) | 1.0% | — | 21 jun 2025 | A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown… |
| CVE-2025-6336 | Alta (7.4) | 0.92% | — | 20 jun 2025 | A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The… |
| CVE-2025-6302 | Alta (7.4) | 0.95% | — | 20 jun 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument… |
| CVE-2025-6162 | Alta (7.4) | 0.96% | — | 17 jun 2025 | A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST… |
| CVE-2025-6145 | Alta (7.4) | 0.96% | — | 16 jun 2025 | A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formSysLog of the component HTTP POST Request… |
| CVE-2025-6144 | Alta (7.4) | 0.96% | — | 16 jun 2025 | A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formSysCmd of the component HTTP POST… |
| CVE-2025-6143 | Alta (7.4) | 0.96% | — | 16 jun 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formNtp of the component HTTP POST Request Handler. The… |
| CVE-2025-6130 | Alta (7.4) | 0.96% | — | 16 jun 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formStats of the component HTTP POST Request… |
| CVE-2025-6129 | Alta (7.4) | 0.92% | — | 16 jun 2025 | A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The… |
| CVE-2025-6128 | Alta (7.4) | 1.2% | — | 16 jun 2025 | A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknown part of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The… |
| CVE-2025-5911 | Alta (7.4) | 1.1% | — | 10 jun 2025 | A vulnerability was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formDMZ of the component HTTP POST Request… |
| CVE-2025-5910 | Alta (7.4) | 1.1% | — | 10 jun 2025 | A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWsc of the component HTTP… |
| CVE-2025-5909 | Alta (7.4) | 1.4% | — | 10 jun 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formReflashClientTbl of the component HTTP POST Request… |
| CVE-2025-5908 | Alta (7.4) | 1.0% | — | 10 jun 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formIpQoS of the component HTTP POST… |
| CVE-2025-5907 | Alta (7.4) | 6.2% | — | 10 jun 2025 | A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The… |
| CVE-2025-5793 | Alta (7.4) | 0.91% | — | 6 jun 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The… |
| CVE-2025-5792 | Alta (7.4) | 5.8% | — | 6 jun 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formWlanRedirect of the component HTTP POST… |
| CVE-2025-5600 | Crítica (9.3) | 1.2% | — | 4 jun 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2025-28039 | Crítica (9.8) | 1.2% | — | 22 abr 2025 | TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter. |
| CVE-2025-28038 | Crítica (9.8) | 1.2% | — | 22 abr 2025 | TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter. |
| CVE-2023-52032 | Crítica (9.8) | 1.6% | — | 11 ene 2024 | TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function. |
| CVE-2021-42893 | Alta (7.5) | 1.4% | — | 3 jun 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg. |
| CVE-2021-42892 | Media (4.3) | 0.73% | — | 3 jun 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware. |
| CVE-2021-42891 | Alta (7.5) | 1.4% | — | 3 jun 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization. |
| CVE-2021-42890 | Crítica (9.8) | 1.9% | — | 3 jun 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack. |
| CVE-2021-42889 | Alta (7.5) | 1.4% | — | 3 jun 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization. |
| CVE-2021-42888 | Crítica (9.8) | 1.9% | — | 3 jun 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack. |
| CVE-2021-42887 | Crítica (9.8) | 44% | — | 3 jun 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.