Totolink
Totolink N350rt Firmware: vulnerabilidades y CVE
Totolink N350rt Firmware tiene 21 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-51630 | Crítica (9.8) | 0.45% | — | 17 jul 2025 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the function setIpPortFilterRules. |
| CVE-2024-42966 | Crítica (9.8) | 0.60% | — | 15 ago 2024 | Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to… |
| CVE-2024-7462 | Alta (8.7) | 1.3% | — | 5 ago 2024 | A vulnerability classified as critical has been found in TOTOLINK N350RT 9.3.5u.6139_B20201216. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to… |
| CVE-2024-7333 | Alta (8.7) | 1.2% | — | 1 ago 2024 | A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2024-0943 | Media (5.3) | 0.59% | — | 26 ene 2024 | A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to… |
| CVE-2024-0570 | Media (6.9) | 0.80% | — | 16 ene 2024 | A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation leads to… |
| CVE-2023-7219 | Crítica (9.8) | 1.3% | — | 9 ene 2024 | A vulnerability has been found in Totolink N350RT 9.3.5u.6139_B202012 and classified as critical. Affected by this vulnerability is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2023-7218 | Alta (7.2) | 1.3% | — | 8 ene 2024 | A vulnerability, which was classified as critical, was found in Totolink N350RT 9.3.5u.6139_B202012. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads… |
| CVE-2023-7214 | Alta (8.8) | 0.90% | — | 7 ene 2024 | A vulnerability, which was classified as critical, has been found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP… |
| CVE-2023-7213 | Alta (8.8) | 0.90% | — | 7 ene 2024 | A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this vulnerability is the function main of the file /cgi-bin/cstecgi.cgi?action=login&flag=1 of the component HTTP… |
| CVE-2023-7187 | Alta (8.8) | 0.71% | — | 31 dic 2023 | A vulnerability was found in Totolink N350RT 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi?action=login&flag=ie8 of the component HTTP… |
| CVE-2022-36488 | Alta (7.8) | 0.35% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules. |
| CVE-2022-36487 | Alta (7.8) | 1.1% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg. |
| CVE-2022-36486 | Alta (7.8) | 1.1% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile. |
| CVE-2022-36485 | Alta (7.8) | 1.1% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg. |
| CVE-2022-36484 | Alta (7.8) | 0.35% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the function setDiagnosisCfg. |
| CVE-2022-36483 | Alta (7.8) | 0.35% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the pppoeUser parameter. |
| CVE-2022-36482 | Alta (7.8) | 0.91% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the lang parameter in the function setLanguageCfg. |
| CVE-2022-36481 | Alta (7.8) | 1.3% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg. |
| CVE-2022-36480 | Alta (7.8) | 0.35% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg. |
| CVE-2022-36479 | Alta (7.8) | 1.1% | — | 25 ago 2022 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.