Totolink: community verdicts
3 notable / known-exploited Totolink CVEs the community has triaged.
Exploitation first, with newly exploited CVEs rising above old ones
- CVE-2025-13184CRIT 9.8EPSS 11%
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
- CVE-2024-35397HIGH 8.8EPSS 16%
TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
- CVE-2021-46009CRIT 9.8EPSS 12%
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.