Totolink
Totolink T8 Firmware: vulnerabilidades y CVE
Totolink T8 Firmware tiene 26 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses0
Críticas11
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-46419 | Crítica (9.8) | 0.72% | — | 16 sept 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter. |
| CVE-2024-46451 | Crítica (9.8) | 1.2% | — | 16 sept 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter. |
| CVE-2024-46424 | Alta (7.5) | 0.55% | — | 16 sept 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter. |
| CVE-2024-8580 | Crítica (9.2) | 1.3% | — | 8 sept 2024 | A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password.… |
| CVE-2024-8579 | Alta (8.7) | 1.3% | — | 8 sept 2024 | A vulnerability classified as critical has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This affects the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password… |
| CVE-2024-8578 | Alta (8.7) | 1.1% | — | 8 sept 2024 | A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. It has been rated as critical. Affected by this issue is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2024-8577 | Alta (8.7) | 1.1% | — | 8 sept 2024 | A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setStaticDhcpRules of the file… |
| CVE-2024-8576 | Alta (8.7) | 1.1% | — | 8 sept 2024 | A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been classified as critical. Affected is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The… |
| CVE-2024-8575 | Alta (8.7) | 1.1% | — | 8 sept 2024 | A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This issue affects the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument… |
| CVE-2024-8574 | Media (5.3) | 3.1% | — | 8 sept 2024 | A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the… |
| CVE-2024-8573 | Alta (8.7) | 1.4% | — | 8 sept 2024 | A vulnerability, which was classified as critical, was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. This affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The… |
| CVE-2024-8079 | Alta (8.7) | 1.1% | — | 22 ago 2024 | A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been rated as critical. This issue affects the function exportOvpn. The manipulation leads to buffer overflow. The attack may be initiated… |
| CVE-2024-8078 | Alta (8.7) | 1.0% | — | 22 ago 2024 | A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been declared as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to buffer overflow. The attack… |
| CVE-2024-8077 | Media (5.3) | 2.9% | — | 22 ago 2024 | A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os command injection. It is possible to… |
| CVE-2024-8076 | Alta (8.7) | 0.80% | — | 22 ago 2024 | A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this issue is the function setDiagnosisCfg. The manipulation leads to buffer overflow. The attack may be… |
| CVE-2024-8075 | Media (5.3) | 1.9% | — | 22 ago 2024 | A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg. The manipulation leads to os command injection. The… |
| CVE-2024-0944 | Media (5.3) | 1.5% | — | 26 ene 2024 | A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session… |
| CVE-2024-0569 | Media (5.3) | 0.95% | — | 16 ene 2024 | A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation… |
| CVE-2023-24157 | Crítica (9.8) | 2.1% | — | 3 feb 2023 | A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. |
| CVE-2023-24156 | Crítica (9.8) | 2.1% | — | 3 feb 2023 | A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. |
| CVE-2023-24155 | Crítica (9.8) | 0.89% | — | 3 feb 2023 | TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini. |
| CVE-2023-24154 | Crítica (9.8) | 1.9% | — | 3 feb 2023 | TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW. |
| CVE-2023-24153 | Crítica (9.8) | 2.1% | — | 3 feb 2023 | A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. |
| CVE-2023-24152 | Crítica (9.8) | 2.1% | — | 3 feb 2023 | A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. |
| CVE-2023-24151 | Crítica (9.8) | 2.1% | — | 3 feb 2023 | A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. |
| CVE-2023-24150 | Crítica (9.8) | 2.1% | — | 3 feb 2023 | A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet. |