📦 Cp900l Firmware

by Totolink

🔍 What is Cp900l Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-35398

CRITICAL CVSS 9.8 May 28, 2024

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK CP900L routers by exploiting a stack overflow in the setMacFilterRules function. Attackers can send specially crafted r...

CVE-2024-35396

CRITICAL CVSS 9.8 May 24, 2024

This vulnerability involves a hardcoded root password in the TOTOLINK CP900L router's configuration file, allowing attackers to gain administrative access via telnet. Anyone using the affected firmwar...

CVE-2024-35397

HIGH CVSS 8.8 May 28, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CP900L routers by injecting malicious commands into the hostTime parameter of the NTPSyncWithHost function. Attacke...

CVE-2024-35395

HIGH CVSS 8.8 May 24, 2024

This vulnerability involves a hardcoded root password in the TOTOLINK CP900L router's sample shadow file. Attackers can use this password to gain administrative access to affected devices. All users r...

CVE-2024-35400

MEDIUM CVSS 5.3 May 28, 2024

This vulnerability allows remote attackers to cause a stack overflow in TOTOLINK CP900L routers by sending specially crafted requests to the SetPortForwardRules function. Attackers could potentially e...