Totolink
totolink
1,106 CVEs • 155 products
Products (155)
Click to collapseToggle
Products (155)
Click to collapse
CVEs (1,106)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request. |
A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a crafted HTTP request. |
A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS). |
A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication. |
1Totolink 2A720r Firmware X5000r FirmwareNov 21, 2024 Apr 14, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modif...Show more |
1Totolink 2A720r Firmware X5000r FirmwareNov 21, 2024 Apr 14, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modif...Show more |
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter. |
1Totolink 13A3002r Firmware A3002ru V1 FirmwareA3002ru V2 Firmware+10 moreNov 21, 2024 Dec 9, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router. |
1Totolink 8A850r V1 Firmware F1 V2 FirmwareF2 V1 Firmware+5 moreNov 21, 2024 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd sysCmd parameter. |
1Totolink 8A850r V1 Firmware F1 V2 FirmwareF2 V1 Firmware+5 moreNov 21, 2024 Nov 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet to the WAN interface, it is possible to open the web managemen...Show more |
In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user knows their current pas...Show more |
1Totolink 8A3002ru Firmware A702r FirmwareN100re Firmware+5 moreNov 21, 2024 Jan 27, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows...Show more |
11Ciktel CoshipFg Products+8 more18A3002ru Firmware A702r FirmwareEmta Ap Firmwre+15 moreNov 21, 2024 Jan 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702...Show more |
11Ciktel CoshipFg Products+8 more18A3002ru Firmware A702r FirmwareEmta Ap Firmwre+15 moreNov 21, 2024 Jan 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TO...Show more |
1Totolink 8A3002ru Firmware A702r FirmwareN100re Firmware+5 moreNov 21, 2024 Jan 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not neede...Show more |
1Totolink 1A3002ru Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter. |
1Totolink 1A3002ru Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter. |
1Totolink 1A3002ru Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable. |
1Totolink 1A3002ru Firmware Nov 21, 2024 Nov 27, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter. |
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm. |