Skip to main content

Vendor/product archive

totolink / n302r_firmware CVEs

Beta · best-effort

4 CVEs tagged to totolink / n302r_firmware1 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2019-19824

Published Jan 27, 2020

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2019-19825

Published Jan 27, 2020

On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA byp…

CVSS 9.8 · Critical
Showing 1-4 of 4 CVEsPage 1 of 1