📦 A950rg Firmware

by Totolink

🔍 What is A950rg Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-44655

CRITICAL CVSS 9.8 Jul 21, 2025

This vulnerability in TOTOLink routers allows attackers to bypass FTP directory restrictions due to misconfigured vsftpd settings. Attackers can access system files, escalate privileges, or use the co...

CVE-2025-45797

CRITICAL CVSS 9.8 May 8, 2025

This CVE describes a critical buffer overflow vulnerability in TOTOlink A950RG routers. Attackers can exploit it by sending specially crafted requests to the setNoticeCfg interface, potentially allowi...

CVE-2025-45800

CRITICAL CVSS 9.8 May 2, 2025

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A950RG routers by exploiting improper input validation in the setDeviceName interface. Attackers can gain full cont...

CVE-2025-28034

CRITICAL CVSS 9.8 Apr 22, 2025

This CVE describes a pre-authentication remote command execution vulnerability in multiple TOTOLINK router models. Attackers can execute arbitrary commands on affected devices without authentication b...

CVE-2022-26206

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a critical command injection vulnerability in multiple Totolink router models. Attackers can execute arbitrary system commands by sending specially crafted requests to the setLangua...

CVE-2022-26208

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the webWlanIdx parameter in the setWebWlanIdx function. ...

CVE-2022-26210

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the FileName parameter in the setUpgradeFW function. Att...

CVE-2022-26212

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the setDeviceName function. Attackers can exploit this b...

CVE-2022-26214

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the host_time parameter in the NTPSyncWithHost function....

CVE-2022-25082

CRITICAL CVSS 9.8 Feb 24, 2022

This CVE describes a command injection vulnerability in TOTOLink A950RG routers that allows attackers to execute arbitrary system commands via the QUERY_STRING parameter. Attackers can gain complete c...

CVE-2025-4496

HIGH CVSS 8.8 May 10, 2025

A critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by manipulating the FileName parameter in the CloudACMunualUpdate function. This affects ...

CVE-2025-28028

HIGH CVSS 7.3 Apr 23, 2025

A buffer overflow vulnerability in TOTOLINK routers' downloadFile.cgi component allows attackers to execute arbitrary code by sending specially crafted requests to the v5 parameter. This affects multi...

CVE-2025-28032

HIGH CVSS 7.3 Apr 22, 2025

This CVE describes a pre-authentication buffer overflow vulnerability in multiple TOTOLINK router models. Attackers can exploit this by sending specially crafted requests to the setNoticeCfg function ...

CVE-2022-28935

HIGH CVSS 7.2 Jul 6, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands on affected devices. The vulnerability affects specific firm...

CVE-2025-60699

MEDIUM CVSS 6.5 Nov 13, 2025

This CVE describes a buffer overflow vulnerability in TOTOLINK A950RG router firmware that allows unauthenticated remote attackers to execute arbitrary code. Attackers can exploit it by sending specia...