TOTOLINK Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for TOTOLINK products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

28

In CISA KEV

0

Beyond CISA KEV

28

Sensor Observed

1

Virtual Patch Available

0

TOTOLINK KEVs Added by Year

Loading...

28 TOTOLINK KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2022-25075

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows...

High Not in CISA 22 Feb 2022
CVE-2021-35327

A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default...

High Not in CISA 05 Aug 2021
CVE-2018-13307

System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST...

High Not in CISA 27 Nov 2018

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 17
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 7
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 2
  • CWE-285 — Improper Authorization 1
  • CWE-287 — Improper Authentication 1
  • CWE-20 — Improper Input Validation 1
  • CWE-862 — Missing Authorization 1
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology