Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2022-27004
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
0
Attacker Value
Unknown
CVE-2022-27003
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
0
Attacker Value
Unknown
CVE-2022-26213
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
0
Attacker Value
Unknown
CVE-2021-45741
Disclosure Date: February 04, 2022 (last updated October 07, 2023)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.
0
Attacker Value
Unknown
CVE-2021-45738
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.
0
Attacker Value
Unknown
CVE-2021-45736
Disclosure Date: February 04, 2022 (last updated October 07, 2023)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.
0
Attacker Value
Unknown
CVE-2021-45735
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.
0
Attacker Value
Unknown
CVE-2021-45734
Disclosure Date: February 04, 2022 (last updated October 07, 2023)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via the url parameter.
0
Attacker Value
Unknown
CVE-2021-45733
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.
0
Attacker Value
Unknown
CVE-2021-27710
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "ip" parameter is directly passed to the attacker, allowing them to control the "ip" field to attack the OS.
0