Vendor
TOTOLINK vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 95 vulnerabilities in TOTOLINK: 1 in the last 7 days and 27 in the last 90 days, 50 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100896, was published on 28 September 2026. 14 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 27
- Critical, all time
- 50
- Exploited in the wild
- 0
About TOTOLINK
TOTOLINK is a manufacturer of network communication products including routers, switches, and wireless adapters.
TOTOLINK technologies
Latest TOTOLINK vulnerabilities
- CVE-2026-100896: TOTOLINK N150RT OS command injection in web management interfacecriticalCVSS 9.9
- CVE-2026-93742: Totolink A3002MU command injection in formWsccriticalCVSS 9.9EPSS 2.3%
- CVE-2026-93741: Totolink A3002MU buffer overflow in formWlWdscriticalCVSS 10EPSS 0.7%
- CVE-2026-93740: Totolink A3002MU buffer overflow in formWlEncryptcriticalCVSS 10EPSS 0.9%
- CVE-2026-93739: Totolink A3002MU buffer overflow in formWlAccriticalCVSS 9.9EPSS 0.9%
- CVE-2026-93738: Totolink A3002MU buffer overflow in formSchedulecriticalCVSS 9.9EPSS 0.9%
- CVE-2026-91853: TOTOLINK X5000R OS command injection in exportOvpn handlerhighCVSS 7.4EPSS 1.8%
- CVE-2026-37152: TOTOLINK X5000R hardcoded root passwordcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-90608: Totolink A3002MU buffer overflow in formPortFwcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-90607: Totolink A3002MU buffer overflow in formNewSchedulecriticalCVSS 9.9EPSS 0.9%
- CVE-2026-90606: Totolink A3002MU buffer overflow in IPv6 setupcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-90605: Totolink A3002MU buffer overflow in formFiltercriticalCVSS 9.9EPSS 0.9%
- CVE-2026-90604: Totolink A3002MU cross-site scripting in web interfacelowCVSS 3.5EPSS 0.4%
- CVE-2026-85031: TOTOLINK CP450 buffer overflow in cstecgi.cgicriticalCVSS 9.9EPSS 0.8%
- CVE-2026-82616: TOTOLINK NR1800X stack-based buffer overflow in setUploadSettingcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-82597: TOTOLINK NR1800X command injection in setUssdhighCVSS 7.4EPSS 1.8%
- CVE-2026-82555: TOTOLINK N600R insufficient randomness in session token generationlowCVSS 3.7EPSS 0.7%
- CVE-2026-82539: TOTOLINK A720R stack buffer overflow in MAC filteringcriticalCVSS 9.1EPSS 0.8%
- CVE-2026-79912: TOTOLINK N600R command injection in cstecgi.cgihighCVSS 8.3EPSS 2.1%
- CVE-2026-79911: TOTOLINK N600R stack-based buffer overflow in setSystemConfigcriticalCVSS 10EPSS 1.1%
- CVE-2026-75013: TOTOLINK EX1200L null pointer dereference in setWizardCfgmediumCVSS 6.5EPSS 0.7%
- CVE-2026-75012: TOTOLINK EX1200L null pointer dereference in Password Configuration HandlermediumCVSS 6.5EPSS 0.7%
- CVE-2026-19847: TOTOLINK A800R stack-based buffer overflow in setWiFiWpsConfighighCVSS 8.8EPSS 0.9%
- CVE-2026-19846: TOTOLINK A800R stack-based buffer overflow in setUrlFilterRuleshighCVSS 8.8EPSS 0.9%
- CVE-2026-15701: Totolink NR1800X stack overflow in Form_LogoutcriticalCVSS 9.8
Most severe TOTOLINK vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-79911: TOTOLINK N600R stack-based buffer overflow in setSystemConfigcriticalCVSS 10EPSS 1.1%
- CVE-2026-93740: Totolink A3002MU buffer overflow in formWlEncryptcriticalCVSS 10EPSS 0.9%
- CVE-2026-93741: Totolink A3002MU buffer overflow in formWlWdscriticalCVSS 10EPSS 0.7%
- CVE-2026-93742: Totolink A3002MU command injection in formWsccriticalCVSS 9.9EPSS 2.3%
- CVE-2026-93739: Totolink A3002MU buffer overflow in formWlAccriticalCVSS 9.9EPSS 0.9%
- CVE-2026-93738: Totolink A3002MU buffer overflow in formSchedulecriticalCVSS 9.9EPSS 0.9%
- CVE-2026-90608: Totolink A3002MU buffer overflow in formPortFwcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-90607: Totolink A3002MU buffer overflow in formNewSchedulecriticalCVSS 9.9EPSS 0.9%
- CVE-2026-90606: Totolink A3002MU buffer overflow in IPv6 setupcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-90605: Totolink A3002MU buffer overflow in formFiltercriticalCVSS 9.9EPSS 0.9%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 1 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 2 | 0 | |
| 24 Aug 2026 | 4 | 2 | |
| 31 Aug 2026 | 3 | 2 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 12 | 10 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 1 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/totolink.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "TOTOLINK vulnerabilities", https://junglewise.ai/threats/vendors/totolink, 28 September 2026.