TOTOLINK vendor intelligence

TOTOLINK Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting TOTOLINK products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
29
Known exploited vulnerabilities affecting TOTOLINK products
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
29
Additional exploited CVEs absent from CISA KEV
Sensor Observed
2
TOTOLINK KEVs with sensor-observed exploitation activity

The catalog gap matters for TOTOLINK exposure

29 of the 29 exploited TOTOLINK CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.

0%
Covered by CISA
100%
Beyond CISA
19
Product families

Attested TOTOLINK CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2025-52907

TOTOLINK X6000R Security Bypass Vulnerability

X6000R High Beyond CISA 17 Aug 2026
CVE-2026-1623

Totolink A7000R cstecgi.cgi setUpgradeFW command injection

A7000R Confirmed Beyond CISA 30 Jul 2026
CVE-2024-34257

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary...

EX1800T High Beyond CISA 14 Feb 2026
CVE-2019-19825

On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the...

Realtek SDK based routers High Beyond CISA 27 Nov 2025
CVE-2023-52028

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.

A3700R High Beyond CISA 07 Jul 2025
CVE-2023-46574

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the...

A3700R High Beyond CISA 07 Jul 2025
CVE-2025-6485

TOTOLINK A3002R formWlSiteSurvey os command injection

A3002R High Beyond CISA 22 Jun 2025
CVE-2021-43711

The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The...

EX200 High Beyond CISA 05 Jun 2025
CVE-2025-4270

TOTOLINK A720R Config cstecgi.cgi information disclosure

A720R High Beyond CISA 05 May 2025
CVE-2025-44846

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl...

CA600-PoE High Beyond CISA 01 May 2025
CVE-2019-19824

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the...

Realtek SDK based routers Confirmed Beyond CISA 25 Apr 2025
CVE-2018-13315

Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an...

A3002RU High Beyond CISA 26 Apr 2025
CVE-2025-3987

TOTOLINK N150RT formWsc command injection

N150RT High Beyond CISA 27 Apr 2025
CVE-2025-28036

TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through...

A950RG High Beyond CISA 22 Apr 2025
CVE-2025-28137

The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function...

A810R High Beyond CISA 15 Apr 2025
CVE-2024-9001

TOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injection

T10 High Beyond CISA 19 Sep 2024
CVE-2024-2353

Totolink X6000R shttpd cstecgi.cgi setDiagnosisCfg os command injection

X6000R High Beyond CISA 10 Mar 2024
CVE-2024-24329

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the...

A3300R High Beyond CISA 30 Jan 2024
CVE-2024-24328

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the...

A3300R High Beyond CISA 30 Jan 2024
CVE-2024-0297

Totolink N200RE cstecgi.cgi UploadFirmwareFile os command injection

N200RE High Beyond CISA 08 Jan 2024
CVE-2024-0292

Totolink LR1200GB cstecgi.cgi setOpModeCfg os command injection

LR1200GB High Beyond CISA 08 Jan 2024
CVE-2022-28912

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW.

N600R High Beyond CISA 10 May 2022
CVE-2022-28908

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in...

N600R High Beyond CISA 10 May 2022
CVE-2022-28907

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.

N600R High Beyond CISA 10 May 2022
CVE-2022-28906

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.

N600R High Beyond CISA 10 May 2022
CVE-2022-26186

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.

N600R High Beyond CISA 22 Mar 2022
CVE-2022-25075

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows...

A3000RU High Beyond CISA 22 Feb 2022
CVE-2021-35327

A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default...

A720R High Beyond CISA 05 Aug 2021
CVE-2018-13307

System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST...

A3002RU High Beyond CISA 27 Nov 2018

Showing 29 of 29 TOTOLINK known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, neutralization, and neutralization account for 26 mapped occurrences across this TOTOLINK KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.