References https://www.sentinelone.com/vulnerability-database/cve-2026-10187/ https://vuldb.com/submit/597681 http://www.sxxdckj.com/cms/a/TOTOLINK-X5000R-he-A7000R-huan-chong-qu-yi-chu-lou-dong.html https://www.sentinelone.com/vulnerability-database/cve-2025-5737/ https://research.qianxin.com/archives/2586 https://telecom.cnvd.org.cn/?max=20&offset=40 https://cve.imfht.com/detail/CVE-2025-1340 https://www.thehackerwire.com/critical-rce-alert-cve-2025-14964-exposes-totolink-t10-to-remote-stack-buffer-overflow/ https://hisecure.hinet.net/secureinfo/popup2.php?cert_id=HiNet-2025-0027 https://wlfw.zepc.edu.cn/info/1712/55102.htm https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/ https://avd.aliyun.com/detail?id=AVD-2022-29391 https://www.cnvd.org.cn/flaw/show/CNVD-2022-50669 https://blog.csdn.net/qq_67181251/article/details/140076753 https://www.thehackerwire.com/totolink-wa300-critical-buffer-overflow-via-http_host/ https://nvd.nist.gov/vuln/detail/CVE-2025-60688 https://app.opencve.io/cve/?vendor=totolink https://www.ameeba.com/blog/cve-2025-6825-critical-buffer-overflow-vulnerability-in-totolink-a702r/ https://www.ameeba.com/blog/cve-2025-5789-critical-buffer-overflow-vulnerability-in-totolink-x15/ https://cve.imfht.com/intel/431121?lang=en https://www.clouddefense.ai/cve/2023/CVE-2023-33485 https://nvd.nist.gov/vuln/detail/CVE-2026-7218 https://sleepyreaper.io/000_Blog/AI-Driven-Binary-Analysis-on-a-TOTOLINK-Router---Shooting-Bugs-In-A-Barrel https://labs.epubit.com/articleDetails?id=NC7E3EF903AE000019342128B14FA1ED0 https://www.sentinelone.com/vulnerability-database/cve-2025-5671/ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alerts/7ae41f0d-12bc-4b4f-8ece-1ee5bd04d5c1/ https://www.chtsecurity.com/news/8aa31e69-1e7c-4186-8554-7d5d6baeaa84 https://github.com/H4lo/awesome-IoT-security-article https://kb.netgear.com/zh_CN/000064488/%E9%92%88%E5%AF%B9%E5%9F%BA%E9%A2%84%E9%AA%8C%E8%AF%81%E7%BC%93%E5%86%B2%E5%8C%BA%E6%BA%A2%E5%87%BA%E7%9A%84%E5%89%8A%E8%AF%81%E7%BC%93%E5%86%B2%E5%8C%BA%E6%BA%A2%E5%87%BA%E7%9A%84%E5%91%8A-PSV-2020-0323 https://github.com/advisories/GHSA-g776-ww5q-qfqq https://github.com/advisories/ghsa-wv35-4hfx-h763 https://pentest-tools.com/vulnerabilities-exploits/totolink-router-remote-command-execution_27315 https://www.sentinelone.com/vulnerability-database/cve-2025-5734/ https://app.opencve.io/cve/?page=2&product=n350rt&vendor=totolink https://github.com/advisories/GHSA-wjgf-7c7g-5vwr https://www.tp-link.com/us/support/faq/5113/ https://blog.talosintelligence.com/vulnerability-roundup-march-20-2024/
Related VulnerabilitiesPoCCVE-2026-19598: Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX RouterPoCCVE-2026-19900: LB-LINK Routers - Unauthenticated Command Injection9Router /api/cli-tools/cowork-settings 命令执行漏洞(CVE-2026-63732)PoCCVE-2026-46339: 9Router <= 0.4.36 - Unauthenticated RCEPoCCVE-2026-59801: 9Router - Unauthenticated LLM Provider API ExposurePoC9router-default-login: 9Router - Default Login9Router /api/cli-tools/cowork-settings 命令执行漏洞(CVE-2026-46339)9router /api/tunnel/tailscale-install 命令执行漏洞PoCCVE-2026-54236: vLLM <= 0.23.0 - Anthropic Router Heap Address Information LeakPoCBLINK Routers /goform/set_cmd 命令执行漏洞(CVE-2025-1609)TOTOLINK EX200 /cgi-bin/cstecgi.cgi setLanguageCfg 命令执行漏洞TOTOLINK EX200 /cgi-bin/cstecgi.cgi NTPSyncWithHost 命令执行漏洞BLINK routers /goform/set_hidessid_cfg 命令执行漏洞(CVE-2025-45985)