{"schema_version":1,"title":"TOTOLINK vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 95 vulnerabilities in TOTOLINK: 1 in the last 7 days and 27 in the last 90 days, 50 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100896, was published on 28 September 2026. 14 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/totolink","json_url":"https://junglewise.ai/threats/vendors/totolink.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/totolink","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":18,"all_time":95,"critical":50,"exploited":0,"last_7_days":1,"last_30_days":18,"last_90_days":27,"last_365_days":90},"latest":[{"cve":"CVE-2026-100896","cvss":9.9,"slug":"cve-2026-100896-a-weakness-has-been-identified-in-totolink-n150rt-3-4-0","title":"TOTOLINK N150RT OS command injection in web management interface","severity":"critical","exploited":false,"published_at":"2026-09-28T02:17:19.617+00:00","url":"https://junglewise.ai/threats/cve-2026-100896-a-weakness-has-been-identified-in-totolink-n150rt-3-4-0"},{"cve":"CVE-2026-93742","cvss":9.9,"epss":0.0227,"slug":"cve-2026-93742-a-weakness-has-been-identified-in-totolink-a3002mu-hh-b20211125","title":"Totolink A3002MU command injection in formWsc","severity":"critical","exploited":false,"published_at":"2026-09-19T09:16:34.74+00:00","url":"https://junglewise.ai/threats/cve-2026-93742-a-weakness-has-been-identified-in-totolink-a3002mu-hh-b20211125"},{"cve":"CVE-2026-93741","cvss":10,"epss":0.0066,"slug":"cve-2026-93741-a-security-flaw-has-been-discovered-in-totolink-a3002mu-hh","title":"Totolink A3002MU buffer overflow in formWlWds","severity":"critical","exploited":false,"published_at":"2026-09-19T06:16:30.557+00:00","url":"https://junglewise.ai/threats/cve-2026-93741-a-security-flaw-has-been-discovered-in-totolink-a3002mu-hh"},{"cve":"CVE-2026-93740","cvss":10,"epss":0.0088,"slug":"cve-2026-93740-a-vulnerability-was-identified-in-totolink-a3002mu-hh-b20211125","title":"Totolink A3002MU buffer overflow in formWlEncrypt","severity":"critical","exploited":false,"published_at":"2026-09-18T22:17:10.89+00:00","url":"https://junglewise.ai/threats/cve-2026-93740-a-vulnerability-was-identified-in-totolink-a3002mu-hh-b20211125"},{"cve":"CVE-2026-93739","cvss":9.9,"epss":0.0085,"slug":"cve-2026-93739-a-vulnerability-was-determined-in-totolink-a3002mu-hh-b20211125","title":"Totolink A3002MU buffer overflow in formWlAc","severity":"critical","exploited":false,"published_at":"2026-09-18T22:17:10.71+00:00","url":"https://junglewise.ai/threats/cve-2026-93739-a-vulnerability-was-determined-in-totolink-a3002mu-hh-b20211125"},{"cve":"CVE-2026-93738","cvss":9.9,"epss":0.0085,"slug":"cve-2026-93738-a-vulnerability-was-found-in-totolink-a3002mu-hh-b20211125-1046","title":"Totolink A3002MU buffer overflow in formSchedule","severity":"critical","exploited":false,"published_at":"2026-09-18T21:18:48.66+00:00","url":"https://junglewise.ai/threats/cve-2026-93738-a-vulnerability-was-found-in-totolink-a3002mu-hh-b20211125-1046"},{"cve":"CVE-2026-91853","cvss":7.4,"epss":0.0182,"slug":"cve-2026-91853-totolink-x5000r-os-command-injection-in-exportovpn-handler","title":"TOTOLINK X5000R OS command injection in exportOvpn handler","severity":"high","exploited":false,"published_at":"2026-09-15T17:17:39.5+00:00","url":"https://junglewise.ai/threats/cve-2026-91853-totolink-x5000r-os-command-injection-in-exportovpn-handler"},{"cve":"CVE-2026-37152","cvss":9.8,"epss":0.0051,"slug":"cve-2026-37152-totolink-x5000r-hardcoded-root-password","title":"TOTOLINK X5000R hardcoded root password","severity":"critical","exploited":false,"published_at":"2026-09-15T16:17:08.533+00:00","url":"https://junglewise.ai/threats/cve-2026-37152-totolink-x5000r-hardcoded-root-password"},{"cve":"CVE-2026-90608","cvss":9.9,"epss":0.0085,"slug":"cve-2026-90608-totolink-a3002mu-buffer-overflow-in-formportfw","title":"Totolink A3002MU buffer overflow in formPortFw","severity":"critical","exploited":false,"published_at":"2026-09-14T01:16:28.13+00:00","url":"https://junglewise.ai/threats/cve-2026-90608-totolink-a3002mu-buffer-overflow-in-formportfw"},{"cve":"CVE-2026-90607","cvss":9.9,"epss":0.0085,"slug":"cve-2026-90607-totolink-a3002mu-buffer-overflow-in-formnewschedule","title":"Totolink A3002MU buffer overflow in formNewSchedule","severity":"critical","exploited":false,"published_at":"2026-09-14T01:16:27.87+00:00","url":"https://junglewise.ai/threats/cve-2026-90607-totolink-a3002mu-buffer-overflow-in-formnewschedule"},{"cve":"CVE-2026-90606","cvss":9.9,"epss":0.0085,"slug":"cve-2026-90606-totolink-a3002mu-buffer-overflow-in-ipv6-setup","title":"Totolink A3002MU buffer overflow in IPv6 setup","severity":"critical","exploited":false,"published_at":"2026-09-14T00:16:57.617+00:00","url":"https://junglewise.ai/threats/cve-2026-90606-totolink-a3002mu-buffer-overflow-in-ipv6-setup"},{"cve":"CVE-2026-90605","cvss":9.9,"epss":0.0085,"slug":"cve-2026-90605-totolink-a3002mu-buffer-overflow-in-formfilter","title":"Totolink A3002MU buffer overflow in formFilter","severity":"critical","exploited":false,"published_at":"2026-09-14T00:16:57.447+00:00","url":"https://junglewise.ai/threats/cve-2026-90605-totolink-a3002mu-buffer-overflow-in-formfilter"},{"cve":"CVE-2026-90604","cvss":3.5,"epss":0.0035,"slug":"cve-2026-90604-totolink-a3002mu-cross-site-scripting-in-web-interface","title":"Totolink A3002MU cross-site scripting in web interface","severity":"low","exploited":false,"published_at":"2026-09-14T00:16:57.28+00:00","url":"https://junglewise.ai/threats/cve-2026-90604-totolink-a3002mu-cross-site-scripting-in-web-interface"},{"cve":"CVE-2026-85031","cvss":9.9,"epss":0.0079,"slug":"cve-2026-85031-totolink-cp450-buffer-overflow-in-cstecgi-cgi","title":"TOTOLINK CP450 buffer overflow in cstecgi.cgi","severity":"critical","exploited":false,"published_at":"2026-09-03T13:06:19.767+00:00","url":"https://junglewise.ai/threats/cve-2026-85031-totolink-cp450-buffer-overflow-in-cstecgi-cgi"},{"cve":"CVE-2026-82616","cvss":9.9,"epss":0.0085,"slug":"cve-2026-82616-totolink-nr1800x-stack-based-buffer-overflow-in-setuploadsetting","title":"TOTOLINK NR1800X stack-based buffer overflow in setUploadSetting","severity":"critical","exploited":false,"published_at":"2026-08-31T05:17:06.393+00:00","url":"https://junglewise.ai/threats/cve-2026-82616-totolink-nr1800x-stack-based-buffer-overflow-in-setuploadsetting"},{"cve":"CVE-2026-82597","cvss":7.4,"epss":0.0182,"slug":"cve-2026-82597-totolink-nr1800x-command-injection-in-setussd","title":"TOTOLINK NR1800X command injection in setUssd","severity":"high","exploited":false,"published_at":"2026-08-31T01:16:50.19+00:00","url":"https://junglewise.ai/threats/cve-2026-82597-totolink-nr1800x-command-injection-in-setussd"},{"cve":"CVE-2026-82555","cvss":3.7,"epss":0.0066,"slug":"cve-2026-82555-totolink-n600r-insufficient-randomness-in-session-token","title":"TOTOLINK N600R insufficient randomness in session token generation","severity":"low","exploited":false,"published_at":"2026-08-30T18:17:00.38+00:00","url":"https://junglewise.ai/threats/cve-2026-82555-totolink-n600r-insufficient-randomness-in-session-token"},{"cve":"CVE-2026-82539","cvss":9.1,"epss":0.0083,"slug":"cve-2026-82539-totolink-a720r-stack-buffer-overflow-in-mac-filtering","title":"TOTOLINK A720R stack buffer overflow in MAC filtering","severity":"critical","exploited":false,"published_at":"2026-08-30T11:17:35.067+00:00","url":"https://junglewise.ai/threats/cve-2026-82539-totolink-a720r-stack-buffer-overflow-in-mac-filtering"},{"cve":"CVE-2026-79912","cvss":8.3,"epss":0.0211,"slug":"cve-2026-79912-totolink-n600r-command-injection-in-cstecgi-cgi","title":"TOTOLINK N600R command injection in cstecgi.cgi","severity":"high","exploited":false,"published_at":"2026-08-25T23:17:59.663+00:00","url":"https://junglewise.ai/threats/cve-2026-79912-totolink-n600r-command-injection-in-cstecgi-cgi"},{"cve":"CVE-2026-79911","cvss":10,"epss":0.011,"slug":"cve-2026-79911-totolink-n600r-stack-based-buffer-overflow-in-setsystemconfig","title":"TOTOLINK N600R stack-based buffer overflow in setSystemConfig","severity":"critical","exploited":false,"published_at":"2026-08-25T23:17:59.49+00:00","url":"https://junglewise.ai/threats/cve-2026-79911-totolink-n600r-stack-based-buffer-overflow-in-setsystemconfig"},{"cve":"CVE-2026-75013","cvss":6.5,"epss":0.0066,"slug":"cve-2026-75013-totolink-ex1200l-null-pointer-dereference-in-setwizardcfg","title":"TOTOLINK EX1200L null pointer dereference in setWizardCfg","severity":"medium","exploited":false,"published_at":"2026-08-17T20:16:47.483+00:00","url":"https://junglewise.ai/threats/cve-2026-75013-totolink-ex1200l-null-pointer-dereference-in-setwizardcfg"},{"cve":"CVE-2026-75012","cvss":6.5,"epss":0.0066,"slug":"cve-2026-75012-totolink-ex1200l-null-pointer-dereference-in-password","title":"TOTOLINK EX1200L null pointer dereference in Password Configuration Handler","severity":"medium","exploited":false,"published_at":"2026-08-17T20:16:47.317+00:00","url":"https://junglewise.ai/threats/cve-2026-75012-totolink-ex1200l-null-pointer-dereference-in-password"},{"cve":"CVE-2026-19847","cvss":8.8,"epss":0.0085,"slug":"cve-2026-19847-totolink-a800r-stack-based-buffer-overflow-in-setwifiwpsconfig","title":"TOTOLINK A800R stack-based buffer overflow in setWiFiWpsConfig","severity":"high","exploited":false,"published_at":"2026-08-14T18:17:24.037+00:00","url":"https://junglewise.ai/threats/cve-2026-19847-totolink-a800r-stack-based-buffer-overflow-in-setwifiwpsconfig"},{"cve":"CVE-2026-19846","cvss":8.8,"epss":0.0085,"slug":"cve-2026-19846-totolink-a800r-stack-based-buffer-overflow-in-seturlfilterrules","title":"TOTOLINK A800R stack-based buffer overflow in setUrlFilterRules","severity":"high","exploited":false,"published_at":"2026-08-14T18:17:23.883+00:00","url":"https://junglewise.ai/threats/cve-2026-19846-totolink-a800r-stack-based-buffer-overflow-in-seturlfilterrules"},{"cve":"CVE-2026-15701","cvss":9.8,"slug":"cve-2026-15701-totolink-nr1800x-stack-overflow-in-form-logout","title":"Totolink NR1800X stack overflow in Form_Logout","severity":"critical","exploited":false,"published_at":"2026-07-14T17:16:45.477+00:00","url":"https://junglewise.ai/threats/cve-2026-15701-totolink-nr1800x-stack-overflow-in-form-logout"}],"vendor":{"hub":true,"name":"TOTOLINK","slug":"totolink","homepage":"https://www.totolink.net/","description":"TOTOLINK is a manufacturer of network communication products including routers, switches, and wireless adapters.","url":"https://junglewise.ai/threats/vendors/totolink"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":2,"exploited":0,"vulnerabilities":4},{"week":"2026-08-31","critical":2,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":10,"exploited":0,"vulnerabilities":12},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":1,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2026-79911","cvss":10,"epss":0.011,"slug":"cve-2026-79911-totolink-n600r-stack-based-buffer-overflow-in-setsystemconfig","title":"TOTOLINK N600R stack-based buffer overflow in setSystemConfig","severity":"critical","exploited":false,"published_at":"2026-08-25T23:17:59.49+00:00","url":"https://junglewise.ai/threats/cve-2026-79911-totolink-n600r-stack-based-buffer-overflow-in-setsystemconfig"},{"cve":"CVE-2026-93740","cvss":10,"epss":0.0088,"slug":"cve-2026-93740-a-vulnerability-was-identified-in-totolink-a3002mu-hh-b20211125","title":"Totolink A3002MU buffer overflow in formWlEncrypt","severity":"critical","exploited":false,"published_at":"2026-09-18T22:17:10.89+00:00","url":"https://junglewise.ai/threats/cve-2026-93740-a-vulnerability-was-identified-in-totolink-a3002mu-hh-b20211125"},{"cve":"CVE-2026-93741","cvss":10,"epss":0.0066,"slug":"cve-2026-93741-a-security-flaw-has-been-discovered-in-totolink-a3002mu-hh","title":"Totolink A3002MU buffer overflow in formWlWds","severity":"critical","exploited":false,"published_at":"2026-09-19T06:16:30.557+00:00","url":"https://junglewise.ai/threats/cve-2026-93741-a-security-flaw-has-been-discovered-in-totolink-a3002mu-hh"},{"cve":"CVE-2026-93742","cvss":9.9,"epss":0.0227,"slug":"cve-2026-93742-a-weakness-has-been-identified-in-totolink-a3002mu-hh-b20211125","title":"Totolink A3002MU command injection in formWsc","severity":"critical","exploited":false,"published_at":"2026-09-19T09:16:34.74+00:00","url":"https://junglewise.ai/threats/cve-2026-93742-a-weakness-has-been-identified-in-totolink-a3002mu-hh-b20211125"},{"cve":"CVE-2026-93739","cvss":9.9,"epss":0.0085,"slug":"cve-2026-93739-a-vulnerability-was-determined-in-totolink-a3002mu-hh-b20211125","title":"Totolink A3002MU buffer overflow in formWlAc","severity":"critical","exploited":false,"published_at":"2026-09-18T22:17:10.71+00:00","url":"https://junglewise.ai/threats/cve-2026-93739-a-vulnerability-was-determined-in-totolink-a3002mu-hh-b20211125"},{"cve":"CVE-2026-93738","cvss":9.9,"epss":0.0085,"slug":"cve-2026-93738-a-vulnerability-was-found-in-totolink-a3002mu-hh-b20211125-1046","title":"Totolink A3002MU buffer overflow in formSchedule","severity":"critical","exploited":false,"published_at":"2026-09-18T21:18:48.66+00:00","url":"https://junglewise.ai/threats/cve-2026-93738-a-vulnerability-was-found-in-totolink-a3002mu-hh-b20211125-1046"},{"cve":"CVE-2026-90608","cvss":9.9,"epss":0.0085,"slug":"cve-2026-90608-totolink-a3002mu-buffer-overflow-in-formportfw","title":"Totolink A3002MU buffer overflow in formPortFw","severity":"critical","exploited":false,"published_at":"2026-09-14T01:16:28.13+00:00","url":"https://junglewise.ai/threats/cve-2026-90608-totolink-a3002mu-buffer-overflow-in-formportfw"},{"cve":"CVE-2026-90607","cvss":9.9,"epss":0.0085,"slug":"cve-2026-90607-totolink-a3002mu-buffer-overflow-in-formnewschedule","title":"Totolink A3002MU buffer overflow in formNewSchedule","severity":"critical","exploited":false,"published_at":"2026-09-14T01:16:27.87+00:00","url":"https://junglewise.ai/threats/cve-2026-90607-totolink-a3002mu-buffer-overflow-in-formnewschedule"},{"cve":"CVE-2026-90606","cvss":9.9,"epss":0.0085,"slug":"cve-2026-90606-totolink-a3002mu-buffer-overflow-in-ipv6-setup","title":"Totolink A3002MU buffer overflow in IPv6 setup","severity":"critical","exploited":false,"published_at":"2026-09-14T00:16:57.617+00:00","url":"https://junglewise.ai/threats/cve-2026-90606-totolink-a3002mu-buffer-overflow-in-ipv6-setup"},{"cve":"CVE-2026-90605","cvss":9.9,"epss":0.0085,"slug":"cve-2026-90605-totolink-a3002mu-buffer-overflow-in-formfilter","title":"Totolink A3002MU buffer overflow in formFilter","severity":"critical","exploited":false,"published_at":"2026-09-14T00:16:57.447+00:00","url":"https://junglewise.ai/threats/cve-2026-90605-totolink-a3002mu-buffer-overflow-in-formfilter"}],"generated_at":"2026-09-28T04:07:00.156884+00:00","technologies":[{"name":"TOTOLINK A8000RU","slug":"a8000ru","vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/a8000ru"},{"name":"TOTOLINK A3002MU","slug":"a3002mu","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/a3002mu"},{"name":"TOTOLINK CA750-PoE","slug":"ca750-poe","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/ca750-poe"},{"name":"TOTOLINK A7100RU","slug":"a7100ru","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/a7100ru"},{"name":"TOTOLINK NR1800X","slug":"nr1800x","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/nr1800x"},{"name":"TOTOLINK A720R","slug":"a720r","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/a720r"},{"name":"TOTOLINK X5000R","slug":"x5000r","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/x5000r"},{"name":"TOTOLINK A720R firmware","slug":"a720r-firmware","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/a720r-firmware"},{"name":"TOTOLINK LR1200GB","slug":"lr1200gb","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/lr1200gb"},{"name":"TOTOLINK LR1200GB firmware","slug":"lr1200gb-firmware","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/lr1200gb-firmware"},{"name":"TOTOLINK N600R","slug":"n600r","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/n600r"},{"name":"TOTOLINK CP450","slug":"cp450","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/cp450"},{"name":"TOTOLINK EX1200L","slug":"ex1200l","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ex1200l"},{"name":"TOTOLINK NR1800X firmware","slug":"nr1800x-firmware","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/nr1800x-firmware"}]}