← Back

A6000r Firmware

a6000r_firmware

Vendor: Totolink • 13 CVEs

CVEs (13)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1A6000r Firmware
Jun 17, 2026
Apr 4, 2025
5.3 MEDIUM· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipula...Show more
A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Totolink
1A6000r Firmware
Jun 17, 2026
Jan 10, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jan 10, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jan 10, 2025
N/A· v4
5.1 MEDIUM· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jan 10, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jul 23, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jul 22, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jul 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jul 22, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jul 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jul 22, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.
1Totolink
1A6000r Firmware
Jun 17, 2026
Jul 22, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.
1Totolink
1A6000r Firmware
Jul 9, 2026
Jun 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the vif_enable function.