Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2024-8869

Disclosure Date: September 15, 2024 (last updated September 21, 2024)
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-23064

Disclosure Date: February 17, 2023 (last updated October 08, 2023)
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
Attacker Value
Unknown

CVE-2022-38535

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function.
Attacker Value
Unknown

CVE-2022-38534

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function.
Attacker Value
Unknown

CVE-2022-36610

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Attacker Value
Unknown

CVE-2022-36456

Disclosure Date: August 25, 2022 (last updated October 08, 2023)
TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
Attacker Value
Unknown

CVE-2021-43662

Disclosure Date: March 31, 2022 (last updated October 07, 2023)
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.
Attacker Value
Unknown

CVE-2021-45742

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
Attacker Value
Unknown

CVE-2021-45740

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the pin parameter.
Attacker Value
Unknown

CVE-2021-45739

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.