Vulnerabilities > Totolink > A3100R Firmware > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-07-06 | CVE-2022-28935 | Command Injection vulnerability in Totolink products Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B20200730, Totolink A3000RU V5.9c.5185_B20201128, Totolink A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability. | 6.5 |
2022-05-18 | CVE-2022-29646 | Exposure of Resource to Wrong Sphere vulnerability in Totolink A3100R Firmware 4.1.2Cu.5050B20200504/4.1.2Cu.5247B20211129 An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtain sensitive information via a crafted web request. | 5.0 |
2022-03-30 | CVE-2021-46006 | Missing Authentication for Critical Function vulnerability in Totolink A3100R Firmware 5.9C.4577 In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. | 4.0 |
2022-03-30 | CVE-2021-46010 | Use of Insufficiently Random Values vulnerability in Totolink A3100R Firmware 5.9C.4577 Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. | 6.5 |