Skip to main content

Vendor/product archive

totolink / a950rg CVEs

Beta · best-effort

33 CVEs tagged to totolink / a950rg20 Critical, 10 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-67189

Published Feb 3, 2026

A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The urlKeyword parameter is not properly validated, and the fu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67188

Published Feb 3, 2026

A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg interface of the /lib/cste_modules/ipv6.so module. The func…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-67187

Published Feb 3, 2026

A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists in the setIpQosRules interface of /lib/cste_modules/firewall…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-67186

Published Feb 3, 2026

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /lib/cste_modules/firewall.so. The vulnerability occurs beca…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-60702

Published Nov 13, 2025

A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60699

Published Nov 13, 2025

A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `global.so` binary. The `getSaveConfig` function retrieves the `h…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4496

Published May 10, 2025

A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the…

CVSS 8.7 · High
evidence mentions
6
Buzz score
36.0

CVE-2025-45798

Published May 8, 2025

A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/sy…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-45797

Published May 8, 2025

TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the NoticeUrl parameter in the set…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-45800

Published May 2, 2025

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so library, specifically in the p…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-28036

Published Apr 22, 2025

TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2025-28035

Published Apr 22, 2025

TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2025-28034

Published Apr 22, 2025

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2025-28033

Published Apr 22, 2025

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1…

CVSS 7.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-28032

Published Apr 22, 2025

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2022-28935

Published Jul 6, 2022

Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B20200730, Totolink A3000RU V5.…

CVSS 7.2 · High

CVE-2022-26214

Published Mar 15, 2022

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2c…

CVSS 9.8 · Critical
Showing 1-25 of 33 CVEsPage 1 of 2