Show filters
612 Total Results
Displaying 571-580 of 612
Sort by:
Attacker Value
Unknown

CVE-2021-45739

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.
Attacker Value
Unknown

CVE-2021-45738

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.
Attacker Value
Unknown

CVE-2021-45737

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the Host parameter.
Attacker Value
Unknown

CVE-2021-45736

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.
Attacker Value
Unknown

CVE-2021-45735

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.
Attacker Value
Unknown

CVE-2021-45734

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via the url parameter.
Attacker Value
Unknown

CVE-2021-45733

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.
Attacker Value
Unknown

CVE-2021-44247

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.
Attacker Value
Unknown

CVE-2021-44246

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain a stack overflow in the function setNoticeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IpTo parameter.
Attacker Value
Unknown

CVE-2021-43711

Disclosure Date: January 04, 2022 (last updated February 23, 2025)
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.