Skip to main content

Vendor/product archive

totolink / n300rt_firmware CVEs

Beta · best-effort

11 CVEs tagged to totolink / n300rt_firmware2 Critical, 4 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2023-48860

Published Dec 7, 2023

TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19824

Published Jan 27, 2020

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2019-19825

Published Jan 27, 2020

On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA byp…

CVSS 9.8 · Critical
Showing 1-11 of 11 CVEsPage 1 of 1