TOTOLINK Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for TOTOLINK products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

28

In CISA KEV

0

Beyond CISA KEV

28

Sensor Observed

1

Virtual Patch Available

0

TOTOLINK KEVs Added by Year

Loading...

28 TOTOLINK KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-1623

Totolink A7000R cstecgi.cgi setUpgradeFW command injection

Confirmed Not in CISA 30 Jul 2026
CVE-2024-34257

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary...

High Not in CISA 14 Feb 2026
CVE-2019-19825

On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the...

High Not in CISA 27 Nov 2025
CVE-2023-52028

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.

High Not in CISA 07 Jul 2025
CVE-2023-46574

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the...

High Not in CISA 07 Jul 2025
CVE-2025-6485

TOTOLINK A3002R formWlSiteSurvey os command injection

High Not in CISA 22 Jun 2025
CVE-2021-43711

The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The...

High Not in CISA 05 Jun 2025
CVE-2025-4270

TOTOLINK A720R Config cstecgi.cgi information disclosure

High Not in CISA 05 May 2025
CVE-2025-44846

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl...

High Not in CISA 01 May 2025
CVE-2019-19824

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the...

High Not in CISA 25 Apr 2025
CVE-2018-13315

Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an...

High Not in CISA 26 Apr 2025
CVE-2025-3987

TOTOLINK N150RT formWsc command injection

High Not in CISA 27 Apr 2025
CVE-2025-28036

TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through...

High Not in CISA 22 Apr 2025
CVE-2025-28137

The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function...

High Not in CISA 15 Apr 2025
CVE-2024-9001

TOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injection

High Not in CISA 19 Sep 2024
CVE-2024-2353

Totolink X6000R shttpd cstecgi.cgi setDiagnosisCfg os command injection

High Not in CISA 10 Mar 2024
CVE-2024-24329

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the...

High Not in CISA 30 Jan 2024
CVE-2024-24328

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the...

High Not in CISA 30 Jan 2024
CVE-2024-0297

Totolink N200RE cstecgi.cgi UploadFirmwareFile os command injection

High Not in CISA 08 Jan 2024
CVE-2024-0292

Totolink LR1200GB cstecgi.cgi setOpModeCfg os command injection

High Not in CISA 08 Jan 2024
CVE-2022-28912

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW.

High Not in CISA 10 May 2022
CVE-2022-28908

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in...

High Not in CISA 10 May 2022
CVE-2022-28907

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.

High Not in CISA 10 May 2022
CVE-2022-28906

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.

High Not in CISA 10 May 2022
CVE-2022-26186

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.

High Not in CISA 22 Mar 2022

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 17
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 7
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 2
  • CWE-285 — Improper Authorization 1
  • CWE-287 — Improper Authentication 1
  • CWE-20 — Improper Input Validation 1
  • CWE-862 — Missing Authorization 1
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology