CVE-2015-9551: Totolink a850r-v1 Firmware
Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd sysCmd parameter.
Affected products
- Totolink a850r-v1 Firmware: before 1.0.1-b20150707.1612 (fixed in 1.0.1-b20150707.1612)
- Totolink f1-v2 Firmware: before 2.1.1-b20150708.1646 (fixed in 2.1.1-b20150708.1646)
- Totolink f2-v1 Firmware: before 2.1.0-b20150320.1611 (fixed in 2.1.0-b20150320.1611)
- Totolink n150rt-v2 Firmware: before 2.1.1-b20150708.1548 (fixed in 2.1.1-b20150708.1548)
- Totolink n151rt-v2 Firmware: before 1.1-b20150708.1559 (fixed in 1.1-b20150708.1559)
- Totolink n300rh-v2 Firmware: before 2.0.1-b20150708.1625 (fixed in 2.0.1-b20150708.1625)
- Totolink n300rh-v3 Firmware: before 3.0.0-b20150331.0858 (fixed in 3.0.0-b20150331.0858)
- Totolink n300rt-v2 Firmware: before 2.1.1-b20150708.1613 (fixed in 2.1.1-b20150708.1613)
Published 2020-11-24. Last modified 2026-06-17.