VulnSea

TOTOLINK has 23 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 11 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 9.8 (critical), with 15 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-119 (8) and CWE-120 (8). Most affected products: A3002MU (10), a3100r_firmware (6), ex1200t_firmware (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.8
Publish → KEV
Last 90 days
11 prev 0

Products

  • A3002MU 10
  • a3100r_firmware 6
  • ex1200t_firmware 3
  • X5000R 1
  • a7000r_firmware 1
  • ar3100r_firmware 1
23
Total CVEs
15
Critical
0
CISA KEV
0
Exploited

TOTOLINK vulnerabilities

CVEs affecting TOTOLINK, newest first. Open any entry for full detail, references, and exploit status.

23 CVEsRSS

CVE-2026-93742Critical· 9.9
2d ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be init…

MidnightTotolink · A3002MUEPSS 1.9%via NVD
CVE-2026-93741Critical· 10.0
2d ago

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It…

MidnightTotolink · A3002MUEPSS 0.64%via NVD
CVE-2026-93740Critical· 10.0PoC
3d ago

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initi…

AbyssalTotolink · A3002MUEPSS 0.61%via NVD
CVE-2026-93739Critical· 9.9
3d ago

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be per…

MidnightTotolink · A3002MUEPSS 0.49%via NVD
CVE-2026-93738Critical· 9.9
3d ago

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possibl…

MidnightTotolink · A3002MUEPSS 0.50%via NVD
CVE-2026-91853High· 7.4PoC
6d ago

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation…

MidnightTOTOLINK · X5000REPSS 1.4%via NVD
CVE-2026-90608Critical· 9.9PoC
1w ago

A flaw has been found in Totolink A3002MU Hh-B20211125.1046

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It i…

AbyssalTotolink · A3002MUEPSS 0.80%via NVD
CVE-2026-90606Critical· 9.9PoC
1w ago

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to…

AbyssalTotolink · A3002MUEPSS 0.49%via NVD
CVE-2026-90605Critical· 9.9PoC
1w ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to bu…

AbyssalTotolink · A3002MUEPSS 0.47%via NVD
CVE-2026-90604Low· 3.5PoC
1w ago

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is …

TwilightTotolink · A3002MUEPSS 0.20%via NVD
CVE-2026-90607Critical· 9.9PoC
1w ago

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow…

AbyssalTotolink · A3002MUEPSS 0.47%via NVD
CVE-2025-9577Low· 2.5
1y ago

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credenti…

Sunlittotolink · x2000r_firmwareEPSS 0.21%via NVD
CVE-2022-32993Critical· 9.8
4y ago

TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.

TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.

Midnighttotolink · a7000r_firmwareEPSS 0.94%via NVD
CVE-2021-42877High· 7.5
4y ago

TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

Twilighttotolink · ex1200t_firmwareEPSS 1.7%via NVD
CVE-2021-42875Critical· 9.8
4y ago

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.

Midnighttotolink · ex1200t_firmwareEPSS 4.4%via NVD
CVE-2021-42872Critical· 9.8
4y ago

TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.

TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.

Midnighttotolink · ex1200t_firmwareEPSS 6.6%via NVD
CVE-2022-29641High· 7.5
4y ago

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Den…

Twilighttotolink · a3100r_firmwareEPSS 1.2%via NVD
CVE-2021-46010High· 8.8
4y ago

Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration

Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.

Twilighttotolink · a3100r_firmwareEPSS 1.2%via NVD
CVE-2021-46009Critical· 9.8
4y ago

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

Midnighttotolink · a3100r_firmwareEPSS 13%via NVD
CVE-2021-46008High· 8.8
4y ago

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function tur…

Twilighttotolink · a3100r_firmwareEPSS 0.92%via NVD
CVE-2021-46007Critical· 9.8
4y ago

totolink a3100r V5.9c.4577 is vulnerable to os command injection

totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.

Midnighttotolink · ar3100r_firmwareEPSS 2.6%via NVD
CVE-2021-46006Medium· 6.5
4y ago

In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated

In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.

Sunlittotolink · a3100r_firmwareEPSS 5.5%via NVD
CVE-2021-44620Critical· 9.8
4y ago

A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

Midnighttotolink · a3100r_firmwareEPSS 1.4%via NVD
TOTOLINK vulnerabilities (CVEs) · VulnSea