Show filters
612 Total Results
Displaying 581-590 of 612
Sort by:
Attacker Value
Unknown

CVE-2021-34228

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.
Attacker Value
Unknown

CVE-2021-34220

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.
Attacker Value
Unknown

CVE-2021-34215

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.
Attacker Value
Unknown

CVE-2021-34223

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.
Attacker Value
Unknown

CVE-2021-34207

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field.
Attacker Value
Unknown

CVE-2021-34218

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.
Attacker Value
Unknown

CVE-2021-35326

Disclosure Date: August 05, 2021 (last updated November 28, 2024)
A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a crafted HTTP request.
Attacker Value
Unknown

CVE-2021-35327

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.
Attacker Value
Unknown

CVE-2021-35325

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).
Attacker Value
Unknown

CVE-2021-35324

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication.