Totolink
Totolink N200re Firmware: vulnerabilidades y CVE
Totolink N200re Firmware tiene 21 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses2
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-55895 | Crítica (9.1) | 0.34% | — | 15 dic 2025 | TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote). |
| CVE-2025-55893 | Media (6.5) | 1.1% | — | 15 dic 2025 | TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName. |
| CVE-2025-7154 | Baja (2.1) | 2.4% | — | 8 jul 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file /cgi-bin/cstecgi.cgi. The… |
| CVE-2024-1004 | Alta (7.2) | 1.3% | — | 29 ene 2024 | A vulnerability, which was classified as critical, was found in Totolink N200RE 9.3.5u.6139_B20201216. This affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host… |
| CVE-2024-1003 | Alta (8.8) | 1.3% | — | 29 ene 2024 | A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2024-1002 | Alta (8.8) | 1.3% | — | 29 ene 2024 | A vulnerability classified as critical was found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this vulnerability is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2024-1001 | Crítica (9.8) | 1.4% | — | 29 ene 2024 | A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to stack-based buffer overflow. It… |
| CVE-2024-1000 | Alta (8.8) | 1.3% | — | 29 ene 2024 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument… |
| CVE-2024-0999 | Alta (8.8) | 1.5% | — | 29 ene 2024 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2024-0998 | Alta (8.8) | 1.4% | — | 29 ene 2024 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip… |
| CVE-2024-0997 | Alta (8.8) | 1.3% | — | 29 ene 2024 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. Affected by this issue is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument… |
| CVE-2024-0299 | Crítica (9.8) | 3.8% | — | 8 ene 2024 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of… |
| CVE-2024-0298 | Crítica (9.8) | 3.8% | — | 8 ene 2024 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. Affected is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip… |
| CVE-2024-0297 | Crítica (9.8) | 3.8% | — | 8 ene 2024 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument… |
| CVE-2024-0296 | Crítica (9.8) | 3.8% | — | 8 ene 2024 | A vulnerability has been found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This vulnerability affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2023-2790 | Media (5.5) | 0.28% | — | 18 may 2023 | A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The… |
| CVE-2020-23617 | Media (6.1) | 0.57% | — | 2 may 2022 | A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element. |
| CVE-2019-19824 | Alta (8.8) | 25% | — | 27 ene 2020 | On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This… |
| CVE-2019-19823 | Alta (7.5) | 6.4% | — | 27 ene 2020 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0,… |
| CVE-2019-19822 | Alta (7.5) | 8.7% | — | 27 ene 2020 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects… |
| CVE-2019-19825 | Crítica (9.8) | 30% | — | 27 ene 2020 | On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.