Home/Product/totolink n300rt firmware
Product

totolink n300rt firmware

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-32335
all versions
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wirele
5.4MEDIUM
CVE-2024-32334
all versions
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Fir
6.5MEDIUM
CVE-2024-32333
all versions
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewal
4.3MEDIUM
CVE-2024-32332
all versions
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless
6.1MEDIUM
CVE-2024-32327
all versions
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firew
5.5MEDIUM
CVE-2023-48860
all versions
TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can b
9.8CRITICAL
CVE-2020-25499
< 3.4.0-b20201026.2033
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use
8.8HIGH
CVE-2019-19824
<= 3.4.0
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd paramete
8.8HIGH
CVE-2019-19823
<= 3.4.0
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative
7.5HIGH
CVE-2019-19822
<= 3.4.0
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retri
7.5HIGH
CVE-2019-19825
<= 3.4.0
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to t
9.8CRITICAL
threatengine.sh