📦 N600r Firmware

by Totolink

🔍 What is N600r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-51390

CRITICAL CVSS 9.8 Aug 4, 2025

This CVE describes a command injection vulnerability in TOTOLINK N600R routers that allows attackers to execute arbitrary commands on the device. The vulnerability exists in the setWiFiWpsConfig funct...

CVE-2025-22900

CRITICAL CVSS 9.8 Apr 15, 2025

This vulnerability allows remote attackers to execute arbitrary code on Totolink N600R routers by exploiting a stack overflow in the setWanConfig function. Attackers can gain full control of affected ...

CVE-2022-29391

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability is a stack overflow in TOTOLINK N600R routers that allows remote code execution via the comment parameter in the setStaticDhcpConfig function. Attackers can exploit this to take ful...

CVE-2022-29393

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability is a stack overflow in TOTOLINK N600R routers that allows remote code execution via the comment parameter in the setIpQosRules function. Attackers can exploit this to take full cont...

CVE-2022-29395

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability is a stack overflow in TOTOLINK N600R routers that allows remote attackers to execute arbitrary code via the apcliKey parameter in the setWiFiRepeaterConfig function. Attackers can ...

CVE-2022-29397

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK N600R routers by exploiting a stack overflow in the comment parameter. Attackers can gain full control of affected devi...

CVE-2022-29399

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability is a stack overflow in TOTOLINK N600R routers that allows remote code execution via a specially crafted URL parameter. Attackers can exploit this to take full control of affected de...

CVE-2022-28910

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink N600R routers by injecting malicious commands into the devicename parameter. Attackers can gain full control of aff...

CVE-2022-28912

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink N600R routers via command injection in the firmware upgrade filename parameter. Attackers can gain full control of ...

CVE-2022-28906

CRITICAL CVSS 9.8 May 10, 2022

This CVE describes a command injection vulnerability in TOTOLink N600R routers where an attacker can execute arbitrary commands via the langtype parameter. Attackers can gain full control of affected ...

CVE-2022-28908

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink N600R routers via command injection in the ipdoamin parameter. Attackers can gain full control of affected devices,...

CVE-2022-26186

CRITICAL CVSS 9.8 Mar 22, 2022

CVE-2022-26186 is a command injection vulnerability in TOTOLINK N600R routers that allows attackers to execute arbitrary commands on the device via the exportOvpn interface. This affects users of TOTO...

CVE-2022-26188

CRITICAL CVSS 9.8 Mar 22, 2022

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK N600R routers via the NTPSyncWithHost setting. Attackers can gain full control of affected devices without authenti...

CVE-2025-60336

HIGH CVSS 7.5 Oct 22, 2025

A NULL pointer dereference vulnerability in TOTOLINK N600R routers allows attackers to crash the device via specially crafted HTTP requests, causing a denial of service. This affects users running vul...

CVE-2025-60335

HIGH CVSS 7.5 Oct 22, 2025

A NULL pointer dereference vulnerability in TOTOLINK N600R routers allows attackers to crash the device via specially crafted HTTP requests, causing a Denial of Service. This affects users of TOTOLINK...

CVE-2025-60333

HIGH CVSS 7.5 Oct 22, 2025

This vulnerability is a stack overflow in the wepkey2 parameter of the setWiFiMultipleConfig function in TOTOLINK N600R routers. Attackers can exploit it by sending crafted input to cause a Denial of ...

CVE-2025-11444

HIGH CVSS 8.8 Oct 8, 2025

A buffer overflow vulnerability in TOTOLINK N600R routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP requests to the setWiFiBasicConfig function. This affects ...

CVE-2025-9935

HIGH CVSS 7.3 Sep 4, 2025

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK N600R routers via command injection in the web interface. Attackers can take full control of affected devices witho...

CVE-2025-4496

HIGH CVSS 8.8 May 10, 2025

A critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by manipulating the FileName parameter in the CloudACMunualUpdate function. This affects ...