Vulnerabilities > Totolink

DATE CVE VULNERABILITY TITLE RISK
2022-01-04 CVE-2021-43711 Command Injection vulnerability in Totolink Ex200 Firmware 4.0.3C.7646B20201211
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters.
network
low complexity
totolink CWE-77
7.5
2021-08-20 CVE-2021-34207 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field.
network
totolink CWE-79
4.3
2021-08-20 CVE-2021-34215 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.
network
totolink CWE-79
4.3
2021-08-20 CVE-2021-34218 Unspecified vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.
network
low complexity
totolink
5.0
2021-08-20 CVE-2021-34220 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.
network
totolink CWE-79
4.3
2021-08-20 CVE-2021-34223 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.
network
totolink CWE-79
4.3
2021-08-20 CVE-2021-34228 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.
network
totolink CWE-79
4.3
2021-08-05 CVE-2021-35324 Unspecified vulnerability in Totolink A720R Firmware 4.1.5Cu.470B20200911
A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication.
network
low complexity
totolink
7.5
2021-08-05 CVE-2021-35325 Out-of-bounds Write vulnerability in Totolink A720R Firmware 4.1.5Cu.470B20200911
A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).
network
low complexity
totolink CWE-787
5.0
2021-08-05 CVE-2021-35326 Unspecified vulnerability in Totolink A720R Firmware 4.1.5Cu.470B20200911
A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a crafted HTTP request.
network
low complexity
totolink
5.0