Total
17 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-7214 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272785 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
CVE-2023-37149 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function. | |||||
CVE-2023-37148 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function. | |||||
CVE-2023-37146 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. | |||||
CVE-2023-37145 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function. | |||||
CVE-2022-44260 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function. | |||||
CVE-2022-44259 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function. | |||||
CVE-2022-44258 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function. | |||||
CVE-2022-44257 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function. | |||||
CVE-2022-44255 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data. | |||||
CVE-2022-44254 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function. | |||||
CVE-2022-44253 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function. | |||||
CVE-2022-44252 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function. | |||||
CVE-2022-44251 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function. | |||||
CVE-2022-44250 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function. | |||||
CVE-2022-44249 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function. | |||||
CVE-2024-42967 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2024-09-06 | N/A | 9.8 CRITICAL |
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh. |