EX200
16 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for EX200, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
EX200 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High9
- Medium4
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting EX200.
- CVE-2026-15271TOTOLINK EX200 Web boa.conf least privilege violation7.5
- CVE-2026-11620TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation5.3
- CVE-2025-65606Уязвимость функции загрузки прошивки микропрограммного обеспечения роутеров TOTOLINK EX200, позволяющая нарушителю получить полный контроль над устройством7.2
- CVE-2024-7336TOTOLINK EX200 cstecgi.cgi loginauth buffer overflow8.8
- CVE-2024-7335TOTOLINK EX200 getSaveConfig buffer overflow8.8
- CVE-2024-32326TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.6.8
- CVE-2024-32325TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.2.4
- CVE-2024-31815In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh9.1
- CVE-2024-31812In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.6.5
- CVE-2024-31811TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.8.0
- CVE-2024-31808TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.8.8
- CVE-2024-31805TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.6.5
- CVE-2024-31807TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.9.8
- CVE-2024-31817In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.7.5
- CVE-2024-31814TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.8.8
Product grouping is registry-driven, with AI assist and human review. How it works