CVE Tools

N600R

16 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for N600R, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

N600R CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
N600R CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-042
2025-051
2025-061
2025-071
2025-081
2025-092
2025-105
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-083
2026-090

Severity

How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical425%
  • High956%
  • Medium213%
  • Low16%

Latest CVEs

The 15 most recently published vulnerabilities affecting N600R.

  1. CVE-2026-82555TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values3.7
  2. CVE-2026-79912TOTOLINK N600R cstecgi.cgi getCurrentTime command injection8.3
  3. CVE-2026-79911TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow10.0
  4. CVE-2025-60333TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Deni...7.5
  5. CVE-2025-60334TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to cause a Denial of ...7.5
  6. CVE-2025-60335A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.7.5
  7. CVE-2025-60336A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.7.5
  8. CVE-2025-11444TOTOLINK N600R HTTP Request cstecgi.cgi setWiFiBasicConfig buffer overflow8.8
  9. CVE-2025-57623A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.5.3
  10. CVE-2025-9935TOTOLINK N600R cstecgi.cgi sub_4159F8 command injection7.3
  11. CVE-2025-51390TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.9.8
  12. CVE-2025-8181TOTOLINK N600R/X2000R FTP Service vsftpd.conf least privilege violation7.2
  13. CVE-2025-46060Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILENAME component9.8
  14. CVE-2025-4496TOTOLINK T10/A3100R/A950RG/A800R/N600R/A3000RU/A810R cstecgi.cgi CloudACMunualUpdate buffer overflow8.8
  15. CVE-2025-22903TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.4.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store