Skip to main content

Vendor/product archive

totolink / n600r CVEs

Beta · best-effort

38 CVEs tagged to totolink / n600r27 Critical, 8 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-60336

Published Oct 22, 2025

A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60334

Published Oct 22, 2025

TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60333

Published Oct 22, 2025

TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-11444

Published Oct 8, 2025

A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the com…

CVSS 7.4 · High
evidence mentions
6
Buzz score
35.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-51390

Published Aug 4, 2025

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-46060

Published Jun 13, 2025

Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILENAME component

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-4496

Published May 10, 2025

A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the…

CVSS 8.7 · High
evidence mentions
6
Buzz score
36.0

CVE-2025-22903

Published Apr 15, 2025

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-22900

Published Apr 15, 2025

Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 38 CVEsPage 1 of 2