Vulnerabilities > Totolink > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-11-27 CVE-2018-13314 OS Command Injection vulnerability in Totolink A3002Ru Firmware 1.0.8
System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.
network
low complexity
totolink CWE-78
critical
10.0
2018-11-27 CVE-2018-13307 OS Command Injection vulnerability in Totolink A3002Ru Firmware 1.0.8
System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter.
network
low complexity
totolink CWE-78
critical
10.0
2018-11-27 CVE-2018-13306 OS Command Injection vulnerability in Totolink A3002Ru Firmware 1.0.8
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.
network
low complexity
totolink CWE-78
critical
10.0
2018-11-26 CVE-2018-13311 OS Command Injection vulnerability in Totolink A3002Ru Firmware 1.0.8
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.
network
low complexity
totolink CWE-78
critical
10.0
2017-07-17 CVE-2017-1000020 Improper Authentication vulnerability in Ecos Embedded web Servers
SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass.
network
low complexity
ecos greatek totolink CWE-287
critical
10.0