TOTOLINK Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for TOTOLINK products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
28
In CISA KEV
0
Beyond CISA KEV
28
Sensor Observed
1
Virtual Patch Available
0
TOTOLINK KEVs Added by Year
28 TOTOLINK KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-1623
Totolink A7000R cstecgi.cgi setUpgradeFW command injection |
A7000R | Confirmed | Not in CISA | 30 Jul 2026 |
|
CVE-2024-34257
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary... |
EX1800T | High | Not in CISA | 14 Feb 2026 |
|
CVE-2019-19825
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the... |
Realtek SDK based routers | High | Not in CISA | 27 Nov 2025 |
|
CVE-2023-52028
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function. |
A3700R | High | Not in CISA | 07 Jul 2025 |
|
CVE-2023-46574
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the... |
A3700R | High | Not in CISA | 07 Jul 2025 |
|
CVE-2025-6485
TOTOLINK A3002R formWlSiteSurvey os command injection |
A3002R | High | Not in CISA | 22 Jun 2025 |
|
CVE-2021-43711
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The... |
EX200 | High | Not in CISA | 05 Jun 2025 |
|
CVE-2025-4270
TOTOLINK A720R Config cstecgi.cgi information disclosure |
A720R | High | Not in CISA | 05 May 2025 |
|
CVE-2025-44846
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl... |
CA600-PoE | High | Not in CISA | 01 May 2025 |
|
CVE-2019-19824
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the... |
Realtek SDK based routers | High | Not in CISA | 25 Apr 2025 |
|
CVE-2018-13315
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an... |
A3002RU | High | Not in CISA | 26 Apr 2025 |
|
CVE-2025-3987
TOTOLINK N150RT formWsc command injection |
N150RT | High | Not in CISA | 27 Apr 2025 |
|
CVE-2025-28036
TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through... |
A950RG | High | Not in CISA | 22 Apr 2025 |
|
CVE-2025-28137
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function... |
A810R | High | Not in CISA | 15 Apr 2025 |
|
CVE-2024-9001
TOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injection |
T10 | High | Not in CISA | 19 Sep 2024 |
|
CVE-2024-2353
Totolink X6000R shttpd cstecgi.cgi setDiagnosisCfg os command injection |
X6000R | High | Not in CISA | 10 Mar 2024 |
|
CVE-2024-24329
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the... |
A3300R | High | Not in CISA | 30 Jan 2024 |
|
CVE-2024-24328
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the... |
A3300R | High | Not in CISA | 30 Jan 2024 |
|
CVE-2024-0297
Totolink N200RE cstecgi.cgi UploadFirmwareFile os command injection |
N200RE | High | Not in CISA | 08 Jan 2024 |
|
CVE-2024-0292
Totolink LR1200GB cstecgi.cgi setOpModeCfg os command injection |
LR1200GB | High | Not in CISA | 08 Jan 2024 |
|
CVE-2022-28912
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW. |
N600R | High | Not in CISA | 10 May 2022 |
|
CVE-2022-28908
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in... |
N600R | High | Not in CISA | 10 May 2022 |
|
CVE-2022-28907
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost. |
N600R | High | Not in CISA | 10 May 2022 |
|
CVE-2022-28906
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg. |
N600R | High | Not in CISA | 10 May 2022 |
|
CVE-2022-26186
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi. |
N600R | High | Not in CISA | 22 Mar 2022 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 17
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 7
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 2
- CWE-285 — Improper Authorization 1
- CWE-287 — Improper Authentication 1
- CWE-20 — Improper Input Validation 1
- CWE-862 — Missing Authorization 1
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology