Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · totolink

totolink

· 422 Critical

Total CVEs

1,107

Critical

422

Products

159

Search All CVEs →

1,107

Products (159)

x5000r firmware70 CVEsx5000r70 CVEsa3300r firmware64 CVEsa3300r64 CVEsa3002r firmware61 CVEsa3002r61 CVEsx6000r firmware57 CVEsx6000r56 CVEsa3002ru firmware49 CVEsa3100r firmware47 CVEsa3100r47 CVEsx2000r45 CVEsx2000r firmware45 CVEsa3002ru45 CVEsa3700r firmware43 CVEsa3700r43 CVEst639 CVEst6 firmware39 CVEsn600r38 CVEsn600r firmware38 CVEsa7100ru firmware37 CVEsex1200t firmware37 CVEsex1200t37 CVEsa7100ru37 CVEslr35036 CVEslr350 firmware36 CVEsa7000r35 CVEsa7000r firmware35 CVEsa950rg33 CVEsa950rg firmware33 CVEsa702r firmware32 CVEsa702r32 CVEsa810r firmware29 CVEsa720r firmware28 CVEsex1800t28 CVEsex1800t firmware28 CVEsa720r28 CVEsnr1800x27 CVEsnr1800x firmware27 CVEsa810r27 CVEst826 CVEst8 firmware26 CVEsa3000ru firmware25 CVEsx1525 CVEsx15 firmware25 CVEsa830r25 CVEsa830r firmware25 CVEsa3600r firmware25 CVEsa3000ru25 CVEsa3600r24 CVEsca300-poe firmware24 CVEsca300-poe24 CVEsa800r23 CVEsa800r firmware23 CVEst1022 CVEst10 firmware22 CVEsn200re firmware21 CVEsn350rt firmware21 CVEsn350rt21 CVEsn200re21 CVEslr1200gb firmware19 CVEscp45019 CVEscp450 firmware19 CVEsex20019 CVEsex200 firmware19 CVEsn150rt19 CVEsn150rt firmware19 CVEslr1200gb19 CVEsx1814 CVEsx18 firmware14 CVEscp900 firmware13 CVEscp90013 CVEsa6000r13 CVEsa6000r firmware13 CVEsn300rt11 CVEsex1200l11 CVEsex1200l firmware11 CVEsn300rt firmware11 CVEsca600-poe firmware10 CVEsca600-poe10 CVEscp900l firmware8 CVEsa860r firmware8 CVEsa860r8 CVEscp900l8 CVEsn300rh7 CVEsn300rh firmware7 CVEscp300\+ firmware6 CVEscp300\+6 CVEsex300 v26 CVEsex300 v2 firmware6 CVEsn100re firmware5 CVEsn100re5 CVEst10 v24 CVEsn302r firmware4 CVEsa3002ru-v24 CVEsn302r4 CVEsn301rt firmware4 CVEsn301rt4 CVEst10 v2 firmware4 CVEsn302r plus firmware3 CVEsn200re-v53 CVEsn200re-v5 firmware3 CVEswa3003 CVEswa300 firmware3 CVEsn300rh-v33 CVEsn300rh-v3 firmware3 CVEsn302r plus3 CVEsn150rt-v2 firmware2 CVEsf2-v1 firmware2 CVEsa850r-v1 firmware2 CVEslr12002 CVEsn300rh-v22 CVEsn300rh-v2 firmware2 CVEsn350r firmware2 CVEsn350r2 CVEsf2-v12 CVEsa3002ru-v32 CVEsf1-v2 firmware2 CVEsn151rt-v22 CVEsn300rt-v22 CVEsn300rt-v2 firmware2 CVEsf1-v22 CVEsa850r-v12 CVEsa8000ru2 CVEsn151rt-v2 firmware2 CVEslr1200 firmware2 CVEsa8000ru firmware2 CVEsn150rt-v22 CVEsa3002ru-v11 CVEsn100re-v31 CVEsn200re-v31 CVEsn200re-v3 firmware1 CVEsn200re-v41 CVEsn200re-v4 firmware1 CVEsn200re v51 CVEsn200re v5 firmware1 CVEsn210re1 CVEsn210re firmware1 CVEsn300rb1 CVEsn300rb firmware1 CVEscp300 firmware1 CVEscp3001 CVEsar3100r firmware1 CVEsar3100r1 CVEssoho1 CVEsa702r-v3 firmware1 CVEsa702r-v31 CVEsa702r-v2 firmware1 CVEsa702r-v21 CVEswa1200-poe1 CVEswa1200-poe firmware1 CVEsa7000ru firmware1 CVEsa7000ru1 CVEsa6000ub firmware1 CVEsa6000ub1 CVEsa3002ru-v3 firmware1 CVEsa3002ru-v2 firmware1 CVEsa3002ru-v1 firmware1 CVEsn100re-v3 firmware1 CVEs

Recent Vulnerabilities

View all 1,107
CVE-2026-31173MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the interval parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31169MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the week parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31168MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the recHour parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31167MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the mode parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31166MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the hour parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31163MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the dhcpMtu parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31162MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the ttlWay parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31181CRITICAL 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31179MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunPort parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31178CRITICAL 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31177CRITICAL 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31176MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun_user parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31175CRITICAL 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31174MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31172MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31171MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the url parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31165MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31164MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31160MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the provider parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31159MEDIUM 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the password parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31170CRITICAL 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parameter to /cgi-bin/cstecgi.cgi.

CVE-2026-31027CRITICAL 9.8

TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary code execution or denial of service.

CVE-2026-5178MEDIUM 6.3

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument vlanPriLan3 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

CVE-2026-5177MEDIUM 6.3

A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-5176HIGH 7.3

A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument provided results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.