Vulnerabilities > Totolink

DATE CVE VULNERABILITY TITLE RISK
2021-08-05 CVE-2021-35325 Out-of-bounds Write vulnerability in Totolink A720R Firmware 4.1.5Cu.470B20200911
A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).
network
low complexity
totolink CWE-787
7.5
2021-08-05 CVE-2021-35326 Unspecified vulnerability in Totolink A720R Firmware 4.1.5Cu.470B20200911
A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a crafted HTTP request.
network
low complexity
totolink
7.5
2021-08-05 CVE-2021-35327 Missing Authorization vulnerability in Totolink A720R Firmware 4.1.5Cu.470B20200911
A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.
network
low complexity
totolink CWE-862
critical
9.8
2021-04-14 CVE-2021-27710 OS Command Injection vulnerability in Totolink A720R Firmware and X5000R Firmware
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request.
network
low complexity
totolink CWE-78
critical
9.8
2021-04-14 CVE-2021-27708 OS Command Injection vulnerability in Totolink A720R Firmware and X5000R Firmware
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request.
network
low complexity
totolink CWE-78
critical
9.8
2021-01-14 CVE-2020-27368 Files or Directories Accessible to External Parties vulnerability in Totolink A702R Firmware 1.0.0B20161227.1023
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.
local
low complexity
totolink CWE-552
5.5
2020-12-09 CVE-2020-25499 Missing Authorization vulnerability in Totolink products
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'.
network
low complexity
totolink CWE-862
8.8
2020-11-24 CVE-2015-9551 Unspecified vulnerability in Totolink products
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices.
network
low complexity
totolink
critical
9.8
2020-11-24 CVE-2015-9550 Exposure of Resource to Wrong Sphere vulnerability in Totolink products
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices.
network
low complexity
totolink CWE-668
7.5
2020-02-24 CVE-2018-13313 Insecure Storage of Sensitive Information vulnerability in Totolink A3002Ru Firmware 1.0.8
In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password.
network
low complexity
totolink CWE-922
6.5