CVE-2015-9551: Totolink a850r-v1 Firmware

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd sysCmd parameter.

Affected products

  • Totolink a850r-v1 Firmware: before 1.0.1-b20150707.1612 (fixed in 1.0.1-b20150707.1612)
  • Totolink f1-v2 Firmware: before 2.1.1-b20150708.1646 (fixed in 2.1.1-b20150708.1646)
  • Totolink f2-v1 Firmware: before 2.1.0-b20150320.1611 (fixed in 2.1.0-b20150320.1611)
  • Totolink n150rt-v2 Firmware: before 2.1.1-b20150708.1548 (fixed in 2.1.1-b20150708.1548)
  • Totolink n151rt-v2 Firmware: before 1.1-b20150708.1559 (fixed in 1.1-b20150708.1559)
  • Totolink n300rh-v2 Firmware: before 2.0.1-b20150708.1625 (fixed in 2.0.1-b20150708.1625)
  • Totolink n300rh-v3 Firmware: before 3.0.0-b20150331.0858 (fixed in 3.0.0-b20150331.0858)
  • Totolink n300rt-v2 Firmware: before 2.1.1-b20150708.1613 (fixed in 2.1.1-b20150708.1613)

Published 2020-11-24. Last modified 2026-06-17.