📦 N200re Firmware

by Totolink

🔍 What is N200re Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-55895

CRITICAL CVSS 9.1 Dec 15, 2025

This vulnerability allows unauthenticated remote attackers to bypass access controls on TOTOLINK routers. Attackers can send malicious payloads to vulnerable interfaces without logging in, potentially...

CVE-2024-1004

HIGH CVSS 7.2 Jan 29, 2024

A critical stack-based buffer overflow vulnerability exists in the Totolink N200RE router's loginAuth function via the http_host parameter. This allows remote attackers to execute arbitrary code or cr...

CVE-2024-1002

HIGH CVSS 7.2 Jan 29, 2024

A critical stack-based buffer overflow vulnerability exists in Totolink N200RE routers running firmware version 9.3.5u.6139_B20201216. Attackers can remotely exploit this by sending specially crafted ...

CVE-2024-1000

HIGH CVSS 7.2 Jan 29, 2024

A critical stack-based buffer overflow vulnerability in the Totolink N200RE router's web interface allows remote attackers to execute arbitrary code by sending specially crafted requests to the setTra...

CVE-2024-0998

HIGH CVSS 7.2 Jan 29, 2024

A critical stack-based buffer overflow vulnerability exists in Totolink N200RE routers running firmware version 9.3.5u.6139_B20201216. Attackers can remotely exploit this by sending specially crafted ...

CVE-2024-0298

HIGH CVSS 7.3 Jan 8, 2024

This critical vulnerability in Totolink N200RE routers allows remote attackers to execute arbitrary operating system commands via command injection in the setDiagnosisCfg function. Attackers can explo...

CVE-2024-0296

HIGH CVSS 7.3 Jan 8, 2024

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on Totolink N200RE routers by injecting malicious commands into the NTPSyncWithHost parameter. Attack...

CVE-2025-55893

MEDIUM CVSS 6.5 Dec 15, 2025

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK N200RE routers by injecting malicious input into the hostName parameter of the setOpModeCfg function. Attackers can...

CVE-2025-7154

MEDIUM CVSS 6.3 Jul 8, 2025

This critical vulnerability in TOTOLINK N200RE routers allows remote attackers to execute arbitrary operating system commands by manipulating the Hostname parameter in the cgi-bin/cstecgi.cgi endpoint...