📦 X2000r Firmware

by Totolink

🔍 What is X2000r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-51135

CRITICAL CVSS 9.8 Dec 30, 2023

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X2000R routers by exploiting a stack overflow in the password setup function. Attackers can gain full control of affect...

CVE-2023-46548

CRITICAL CVSS 9.8 Oct 25, 2023

This CVE describes a stack overflow vulnerability in the TOTOLINK X2000R router's web interface function formWlanRedirect. Attackers can exploit this remotely without authentication to execute arbitra...

CVE-2023-46550

CRITICAL CVSS 9.8 Oct 25, 2023

This CVE describes a stack overflow vulnerability in TOTOLINK X2000R routers that allows remote attackers to execute arbitrary code. The vulnerability exists in the formMapDelDevice function and affec...

CVE-2023-46552

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability is a stack overflow in the formMultiAP function of TOTOLINK X2000R routers, allowing remote attackers to execute arbitrary code or crash the device. It affects users of TOTOLINK X20...

CVE-2023-46554

CRITICAL CVSS 9.8 Oct 25, 2023

This CVE describes a stack overflow vulnerability in TOTOLINK X2000R routers via the formMapDel function, allowing remote code execution. Attackers can exploit this to take complete control of affecte...

CVE-2023-46556

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability is a stack overflow in the formFilter function of TOTOLINK X2000R routers running firmware version 1.0.0-B20230221.0948.web. It allows remote attackers to execute arbitrary code on ...

CVE-2023-46558

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X2000R routers by exploiting a stack overflow in the formMapDelDevice function. Attackers can gain full control of affe...

CVE-2023-46560

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X2000R routers by exploiting a stack overflow in the formTcpipSetup function. Attackers can gain full control of affect...

CVE-2023-46563

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability is a stack overflow in the formIpQoS function of TOTOLINK X2000R routers running firmware version v1.0.0-B20230221.0948.web. It allows remote attackers to execute arbitrary code or ...

CVE-2023-46540

CRITICAL CVSS 9.8 Oct 25, 2023

This CVE describes a stack overflow vulnerability in the formNtp function of TOTOLINK X2000R routers running firmware version 1.0.0-B20230221.0948.web. Attackers can exploit this to execute arbitrary ...

CVE-2023-46542

CRITICAL CVSS 9.8 Oct 25, 2023

This CVE describes a stack overflow vulnerability in TOTOLINK X2000R routers that allows remote attackers to execute arbitrary code or cause denial of service. The vulnerability exists in the formMesh...

CVE-2023-46544

CRITICAL CVSS 9.8 Oct 25, 2023

This CVE describes a stack overflow vulnerability in TOTOLINK X2000R routers via the formWirelessTbl function. Attackers can exploit this to execute arbitrary code or cause denial of service. Users of...

CVE-2023-46546

CRITICAL CVSS 9.8 Oct 25, 2023

CVE-2023-46546 is a critical stack overflow vulnerability in TOTOLINK X2000R routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the formStats funct...

CVE-2024-28404

HIGH CVSS 8.0 Mar 15, 2024

This stored cross-site scripting (XSS) vulnerability in TOTOLINK X2000R routers allows attackers to inject malicious scripts into the MAC Filtering configuration page. When administrators view the fir...

CVE-2023-7222

HIGH CVSS 7.2 Jan 9, 2024

A critical buffer overflow vulnerability in Totolink X2000R routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests. This affects the formTmultiAP fun...

CVE-2025-5515

MEDIUM CVSS 6.3 Jun 3, 2025

This critical vulnerability in TOTOLINK X2000R routers allows remote attackers to execute arbitrary commands via command injection in the /boafrm/formMapDel endpoint. Attackers can exploit this by man...

CVE-2024-33433

MEDIUM CVSS 4.8 May 14, 2024

This CVE describes a Cross-Site Scripting (XSS) vulnerability in TOTOLINK X2000R routers that allows remote attackers to inject malicious scripts via the Guest Access Control parameter. Attackers can ...