Skip to main content

Vendor archive

totolink CVEs

Beta · best-effort

1,107 CVEs tagged to vendor totolink429 Critical, 429 High, 198 Medium, 51 Low, 0 Unrated.

CVE-2021-34223

Published Aug 20, 2021

Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34220

Published Aug 20, 2021

Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "U…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34218

Published Aug 20, 2021

Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34215

Published Aug 20, 2021

Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Serv…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34207

Published Aug 20, 2021

Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain N…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35327

Published Aug 5, 2021

A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST re…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-35326

Published Aug 5, 2021

A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a crafted HTTP request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35324

Published Aug 5, 2021

A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-9551

Published Nov 24, 2020

An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface…

CVSS 9.8 · Critical

CVE-2019-19824

Published Jan 27, 2020

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2019-19825

Published Jan 27, 2020

On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA byp…

CVSS 9.8 · Critical

CVE-2018-13307

Published Nov 27, 2018

System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1,076-1,100 of 1,107 CVEsPage 44 of 45