PatchSiren

Totolink CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Totolink CVE published 2026-10-05

CVE-2026-105285

A critical vulnerability has been identified in Totolink A3002MU 1.0.0-B20230403.1455, affecting the QoS Rule Handler. The vulnerability is a stack-based buffer overflow, which can be exploited remotely. The exploit has been publicly disclosed. Network administrators and security teams should assess exposure and verify if vendor remediation is available. The vulnerability can lead to a denial of service o [truncated]

MEDIUM Totolink CVE published 2026-10-05

CVE-2026-105286

A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. Defenders should assess exposure and prioritize verification and potential pat [truncated]

CRITICAL Totolink CVE published 2026-10-05

CVE-2026-105284

A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

HIGH TOTOLINK CVE published 2026-09-28

CVE-2026-100896

A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

HIGH Totolink CVE published 2026-09-19

CVE-2026-93742

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vulnerability is a command injection issue in the formWsc function of [truncated]

CRITICAL TOTOLINK CVE published 2026-09-15

CVE-2026-37152

A critical vulnerability was discovered in TOTOLINK X5000R V9.1.0cu.2415_B20250515, which contains a hardcoded password for root access. This issue has a CVSS score of 9.8 and is considered critical. The hardcoded password vulnerability in TOTOLINK X5000R devices requires immediate attention from defenders to assess exposure and verify the presence of hardcoded credentials. Defenders responsible for manag [truncated]

CRITICAL TOTOLINK CVE published 2026-09-01

CVE-2026-51767

The CVE-2026-51767 vulnerability affects TOTOLINK T6 devices with firmware version 4.1.5cu.748_B20211015. This critical vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to reset pairing state and reboot the device via crafted MQTT messages to the cs_broker component. Users and administrators should be aware of the vulnerability's impact on their systems and take immediate action t [truncated]

CRITICAL TOTOLINK CVE published 2026-09-01

CVE-2026-51764

CVE-2026-51764 is a critical vulnerability in TOTOLINK T6 devices. The recvSlaveCloudCheckStatus function has incorrect access control, allowing unauthenticated attackers to overwrite cloud-result tracking files by sending a crafted MQTT message to the cs_broker component. This could lead to significant impacts if exploited, including potential overwriting of cloud-result tracking files. Defenders should [truncated]

CRITICAL TOTOLINK CVE published 2026-09-01

CVE-2026-51762

CVE-2026-51762 is a critical vulnerability in the TOTOLINK T6 4.1.5cu.748_B20211015 meshInfoKick function, allowing unauthenticated attackers to manipulate mesh information/state via crafted MQTT messages to cs_broker. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. Network administrators and security teams should be aware of this vulnerability and take steps to mitigate it. The CVE [truncated]

CRITICAL TOTOLINK CVE published 2026-09-01

CVE-2026-51757

CVE-2026-51757: Executive Overview and Additional Context. The TOTOLINK T6 device, specifically version 4.1.5cu.748_B20211015, is affected by a critical vulnerability in the meshSlaveUpdate function. This function has incorrect access control, allowing unauthenticated attackers to start a firmware download or flash workflow on the slave device via a crafted MQTT message to the cs_broker component. Organiz [truncated]

CRITICAL TOTOLINK CVE published 2026-09-01

CVE-2026-51751

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T14:17:35.667Z and has not been modified since then. CVE-2026-51751 is a critical vulnerability in the TOTOLINK T6 device, specifically affecting the delSlaveDevice function. This function has incorrect access control, allowing unauthenticated attackers to remove specified slave devices from local [truncated]

CRITICAL TOTOLINK CVE published 2026-09-01

CVE-2026-51747

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T13:19:45.610Z and has not been modified since then. The keepAlive function in TOTOLINK T6 4.1.5cu.748_B20211015 has incorrect access control, allowing unauthenticated attackers to emit indirect mesh heartbeat information toward the master by sending a crafted MQTT message to the cs_broker compone [truncated]

CRITICAL TOTOLINK CVE published 2026-09-01

CVE-2026-51744

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T13:19:45.390Z and has not been modified since then. The recv_mesh_info_sync function in TOTOLINK T6 4.1.5cu.748_B20211015 has an incorrect access control vulnerability. This allows unauthenticated attackers to force mesh configuration synchronization by sending a crafted MQTT message to the cs_br [truncated]

CRITICAL TOTOLINK CVE published 2026-09-01

CVE-2026-51741

The CVE-2026-51741 vulnerability affects TOTOLINK T6 devices with firmware version 4.1.5cu.748_B20211015. This critical vulnerability, classified as an incorrect access control issue in the clearDiagnosisLog function, allows unauthenticated attackers to erase diagnosis logs via a crafted POST request to /cgi-bin/cstecgi.cgi. The vulnerability has a CVSS score of 9.8 and is considered CRITICAL. Network adm [truncated]

HIGH TOTOLINK CVE published 2026-08-30

CVE-2026-82539

The CVE-2026-82539 vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509, impacting the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. This vulnerability has a high CVSS score of 8.5, indicating a significant risk of remote exploitation. Affec [truncated]

MEDIUM TOTOLINK CVE published 2026-08-25

CVE-2026-79912

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T23:17:59.663Z and has not been modified since then. The vulnerability, CVE-2026-79912, is a command injection issue in the getCurrentTime function of /cgi-bin/cstecgi.cgi in TOTOLINK N600R 4.3.0cu.7647_B20210106. The vulnerability is triggered by manipulating the ntp_server argument, allowing for [truncated]

HIGH TOTOLINK CVE published 2026-07-09

CVE-2026-15271

A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10, and EX200 up to 20260906. The vulnerability affects some unknown functionality of the file /etc/boa/boa.conf of the component Web Interface, leading to a least privilege violation. The attack may be initiated remotely, with high complexity and difficult exploitation. This vulnerability has a CVSS [truncated]

MEDIUM TOTOLINK CVE published 2026-07-09

CVE-2026-15204

A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely. This vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity.

CRITICAL Totolink CVE published 2026-06-23

CVE-2026-44089

The Totolink EX1200L router is vulnerable to a buffer overflow in the login functionality of the cgi-bin/cstecgi.cgi endpoint. This vulnerability, CVE-2026-44089, could be exploited to cause the program to crash and execute code remotely. An attacker could perform actions as root, including reading and editing data, as well as bricking the router. The vulnerability has been confirmed in version 9.3.5u.614 [truncated]

MEDIUM TOTOLINK CVE published 2026-06-09

CVE-2026-11620

A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results in least privilege violation. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

LOW TOTOLINK CVE published 2026-06-08

CVE-2026-11554

A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

LOW TOTOLINK CVE published 2026-06-08

CVE-2026-11494

A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

HIGH Totolink CVE published 2026-05-26

CVE-2026-9543

A command injection vulnerability in the Totolink N300RH wireless router allows unauthenticated remote attackers to execute arbitrary operating system commands via the Web Management Interface. The vulnerability resides in the `setPasswordCfg` function of `/cgi-bin/cstecgi.cgi`, where the `admpass` parameter is passed unsanitized to a shell command. The CVSS 4.0 score of 8.9 (HIGH) reflects network attack [truncated]

LOW Totolink CVE published 2026-05-26

CVE-2026-9534

A command injection vulnerability in Totolink CA750-PoE 6.2c.510 allows remote attackers to execute arbitrary OS commands via the PIN parameter in the setWiFiWpsConfig function of /cgi-bin/cstecgi.cgi. The vulnerability has a LOW CVSS 4.0 score (2.1) with network attack vector, low attack complexity, and low privileges required. The exploit has been publicly disclosed.

LOW Totolink CVE published 2026-05-26

CVE-2026-9532

A command injection vulnerability exists in the Totolink CA750-PoE 6.2c.510 router firmware. The flaw resides in the `setUploadUserData` function within `/cgi-bin/cstecgi.cgi`, where unsanitized user input via the `FileName` parameter permits arbitrary operating system command execution. The vulnerability is remotely exploitable and requires low privileges (authenticated access). Public exploit disclosure [truncated]

LOW Totolink CVE published 2026-05-26

CVE-2026-9515

A remote OS command injection vulnerability exists in Totolink CA750-PoE firmware version 6.2c.510. The vulnerability resides in the `setUnloadUserData` function within the `/cgi-bin/cstecgi.cgi` Setting Handler component. An authenticated attacker with low privileges can inject arbitrary operating system commands via the `plugin_version` parameter. The CVSS 4.0 vector indicates network attack vector, low [truncated]

LOW Totolink CVE published 2026-05-25

CVE-2026-9514

A command injection vulnerability exists in the Totolink CA750-PoE 6.2c.510 firmware. The setNetworkDiag function in /cgi-bin/cstecgi.cgi fails to sanitize user-supplied input for network diagnostic parameters (NetDiagHost, NetDiagPingNum, NetDiagPingSize, NetDiagPingTimeOut, NetDiagTracertHop), allowing authenticated remote attackers to inject arbitrary operating system commands. The vulnerability requir [truncated]

LOW Totolink CVE published 2026-05-25

CVE-2026-9513

A command injection vulnerability exists in the NTPSyncWithHost function of the /cgi-bin/cstecgi.cgi endpoint on Totolink CA750-PoE devices running firmware version 6.2c.510. The host_time parameter accepts unsanitized input that is passed to a shell command, enabling authenticated remote attackers to execute arbitrary operating system commands. The vulnerability requires low privileges and no user intera [truncated]

LOW Totolink CVE published 2026-05-25

CVE-2026-9512

A command injection vulnerability exists in the Totolink CA750-PoE 6.2c.510 firmware. The flaw resides in the setPasswordCfg function within /cgi-bin/cstecgi.cgi, where unsanitized input for the admuser and admpass parameters allows remote attackers to execute arbitrary operating system commands. The vulnerability requires authentication (PR:L per CVSS 4.0 vector), limiting its immediate exploitability. P [truncated]

HIGH Totolink CVE published 2026-05-25

CVE-2026-9476

A command injection vulnerability exists in the Totolink A8000RU wireless router firmware version 7.1cu.643_b20200521. The vulnerability resides in the `setPasswordCfg` function within the `/cgi-bin/cstecgi.cgi` endpoint of the web management interface. The `admpass` parameter accepts unsanitized input that is passed to a shell command, enabling remote attackers to execute arbitrary operating system comma [truncated]