References https://github.com/zxsssd/TotoLink- http://mchz.com.cn/news/details3404 https://peiqi.wgpsec.org/wiki/iot/TOTOLink/TOTOLink%20%E5%A4%9A%E4%B8%AA%E8%AE%BE%E5%A4%87%20download.cgi%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2022-25084.html https://www.iotsec-zone.com/article/106 https://nvd.nist.gov/vuln/detail/CVE-2025-9935 https://security.bnu.edu.cn/ldgg/129437.html https://www.sxxdckj.com/cms/a/TOTOLINK-N600R-cun-zai-ming-ling-zhi-xing-lou-dong.html https://github.com/doudoudedi/ToTolink_EX200_Cmmand_Execute/blob/main/ToTolink%20EX200%20Comand%20Injection2.md https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=33678 https://www.fortinet.com/blog/threat-research/totolink-vulnerabilities-beastmode-mirai-campaign https://cujo.com/blog/the-2022-2023-iot-botnet-report-vulnerabilities-targeted/ https://www.bankinfosecurity.com/new-mirai-based-campaign-targets-unpatched-totolink-routers-a-18840 https://www.cisa.gov/news-events/bulletins/sb25-111 https://isomer-user-content.by.gov.sg/36/ec404bb0-feb2-447a-a89b-6f976c69febd/31-August-2022.pdf https://github.com/ejdhssh/IOT_Vul
Related VulnerabilitiesTOTOLINK EX200 /cgi-bin/cstecgi.cgi setLanguageCfg 命令执行漏洞TOTOLINK EX200 /cgi-bin/cstecgi.cgi NTPSyncWithHost 命令执行漏洞PoCCVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information DisclosurePoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassPoCCVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command InjectionPoCCVE-2021-42887: TOTOLINK EX1200T 4.1.2cu.5215 - Authentication BypassPoCCVE-2022-25082: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-30013: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-46574: TOTOLINK A3700R - Command InjectionPoCCVE-2024-24328: TotoLink Router setMacFilterRules - Command InjectionPoCCVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection