CVE-2023-4746 – TOTOLINK N200RE V5 Validity_check format string
https://notcve.org/view.php?id=CVE-2023-4746
04 Sep 2023 — A vulnerability classified as critical has been found in TOTOLINK N200RE V5 9.3.5u.6437_B20230519. This affects the function Validity_check. The manipulation leads to format string. It is possible to initiate the attack remotely. The root-cause of the vulnerability is a format string issue. • https://gist.github.com/dmknght/8f3b6aa65e9d08f45b5236c6e9ab8d80 • CWE-134: Use of Externally-Controlled Format String •
CVE-2023-39617
https://notcve.org/view.php?id=CVE-2023-39617
21 Aug 2023 — TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function. • https://sedate-class-393.notion.site/TOTOlink-ee7eb0d4cd5d43e9983296200371eff1?pvs=4 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-39618
https://notcve.org/view.php?id=CVE-2023-39618
21 Aug 2023 — TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface. • https://sedate-class-393.notion.site/TOTOlink-3567fd9f93d84afab0d81cd8c063f9a1?pvs=4 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-4412 – TOTOLINK EX1200L setWanCfg os command injection
https://notcve.org/view.php?id=CVE-2023-4412
18 Aug 2023 — A vulnerability was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This issue affects the function setWanCfg. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://gist.github.com/dmknght/02a29e1c5ae18b45eacc2085d22068e8 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2023-4411 – TOTOLINK EX1200L setTracerouteCfg os command injection
https://notcve.org/view.php?id=CVE-2023-4411
18 Aug 2023 — A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://gist.github.com/dmknght/02a29e1c5ae18b45eacc2085d22068e8 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2023-4410 – TOTOLINK EX1200L setDiagnosisCfg os command injection
https://notcve.org/view.php?id=CVE-2023-4410
18 Aug 2023 — A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://gist.github.com/dmknght/02a29e1c5ae18b45eacc2085d22068e8 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2023-40041
https://notcve.org/view.php?id=CVE-2023-40041
08 Aug 2023 — TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code. • https://github.com/Korey0sh1/IoT_vuln/blob/main/TOTOLINK/T10_V2/lib-cste_modules-wps.md • CWE-787: Out-of-bounds Write •
CVE-2023-40042
https://notcve.org/view.php?id=CVE-2023-40042
08 Aug 2023 — TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code. • http://www.totolink.cn • CWE-787: Out-of-bounds Write •
CVE-2023-34669
https://notcve.org/view.php?id=CVE-2023-34669
17 Jul 2023 — TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system. • https://w3b5h3ll.notion.site/w3b5h3ll/TOTOLINK-CP300-c96d775881f0476b9ef465dba9c6d9b8 • CWE-203: Observable Discrepancy •
CVE-2023-37145
https://notcve.org/view.php?id=CVE-2023-37145
07 Jul 2023 — TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function. • https://github.com/DaDong-G/Vulnerability_info/blob/main/TOTOLINK/lr350/1/Readme.md • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •