totolink security advisories
10 threat alerts tracking vulnerabilities and security advisories that affect totolink products.
Vulnios monitors totolink CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent totolink security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2025-13184 — totolink — x5000r_firmware, x5000r
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution)
criticalCVE-2025-13184Critical Vulnerability: CVE-2024-35396 — totolink — cp900l_firmware, cp900l
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.
criticalCVE-2024-35396Critical Vulnerability: CVE-2024-35398 — totolink — cp900l_firmware, cp900l
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules.
criticalCVE-2024-35398Critical Vulnerability: CVE-2023-31569 — totolink — x5000r_firmware, x5000r
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
criticalCVE-2023-31569Critical Vulnerability: CVE-2023-31729 — totolink — a3300r_firmware, a3300r
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
criticalCVE-2023-31729Critical Vulnerability: CVE-2024-52723 — totolink — x6000r_firmware, x6000r
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing
criticalCVE-2024-52723Critical Vulnerability: CVE-2026-31181 — totolink — a3300r_firmware, a3300r
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi.
criticalCVE-2026-31181Critical Vulnerability: CVE-2026-31175 — totolink — a3300r_firmware, a3300r
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.
criticalCVE-2026-31175Critical Vulnerability: CVE-2026-31177 — totolink — a3300r_firmware, a3300r
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi.
criticalCVE-2026-31177Critical Vulnerability: CVE-2026-31178 — totolink — a3300r_firmware, a3300r
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi.
criticalCVE-2026-31178
Track totolink exposure across your environment
Vulnios automatically cross-references your asset inventory against new totolink CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan