cbcvebase.

Totolink A3100R Firmware vulnerabilities

47 known vulnerabilities affecting totolink/a3100r_firmware.

Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
3
Severity breakdown
CRITICAL25HIGH20MEDIUM2

Vulnerabilities

Page 1 of 3
CVE-2022-25077P1CRITICALCVSS 9.8Exploitedv4.1.2cu.5050_b202005042022-02-24
CVE-2022-25077 [CRITICAL] CWE-78 CVE-2022-25077: TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
nvd
CVE-2022-26210P1CRITICALCVSS 9.8Exploitedv4.1.2cu.5050_b202005042022-03-15
CVE-2022-26210 [CRITICAL] CWE-78 CVE-2022-26210: Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUpgradeFW, via the FileName parameter. This vulnerability allows attackers
nvd
CVE-2025-28036P1CRITICALCVSS 9.8Exploitedv4.1.2cu.5247_b202111292025-04-22
CVE-2025-28036 [CRITICAL] CWE-78 CVE-2025-28036: TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vul TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
nvd
CVE-2024-7157P2HIGHCVSS 8.8v4.1.2cu.5050_b202005042024-07-28
CVE-2024-7157 [HIGH] CWE-120 CVE-2024-7157: A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been classified as criti A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been classified as critical. This affects the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_host leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the p
nvd
CVE-2024-7158P2HIGHCVSS 8.8v4.1.2cu.5050_b202005042024-07-28
CVE-2024-7158 [HIGH] CWE-77 CVE-2024-7158: A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been declared as critica A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been declared as critical. This vulnerability affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument telnet_enabled leads to command injection. The attack can be initiated remotely. The explo
nvd
CVE-2022-26208P2CRITICALCVSS 9.8v4.1.2cu.5050_b202005042022-03-15
CVE-2022-26208 [CRITICAL] CWE-78 CVE-2022-26208: Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setWebWlanIdx, via the webWlanIdx parameter. This vulnerability allows attack
nvd
CVE-2022-26207P2CRITICALCVSS 9.8v4.1.2cu.5050_b202005042022-03-15
CVE-2022-26207 [CRITICAL] CWE-78 CVE-2022-26207: Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setDiagnosisCfg, via the ipDoamin parameter. This vulnerability allows attack
nvd
CVE-2022-26209P2CRITICALCVSS 9.8v4.1.2cu.5050_b202005042022-03-15
CVE-2022-26209 [CRITICAL] CWE-78 CVE-2022-26209: Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attac
nvd
CVE-2022-26206P2CRITICALCVSS 9.8v4.1.2cu.5050_b202005042022-03-15
CVE-2022-26206 [CRITICAL] CWE-78 CVE-2022-26206: Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setLanguageCfg, via the langType parameter. This vulnerability allows attacke
nvd
CVE-2025-4496P2CRITICALCVSS 9.8v4.1.8cu.5241_b202109272025-05-10
CVE-2025-4496 [CRITICAL] CWE-119 CVE-2025-4496: A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5 A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffer overflow. The attack can be initiated remotely. Th
nvd
CVE-2022-26212P2CRITICALCVSS 9.8v4.1.2cu.5050_b202005042022-03-15
CVE-2022-26212 [CRITICAL] CWE-78 CVE-2022-26212: Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setDeviceName, via the deviceMac and deviceName parameters. This vulnerabilit
nvd
CVE-2022-26211P2CRITICALCVSS 9.8v4.1.2cu.5050_b202005042022-03-15
CVE-2022-26211 [CRITICAL] CWE-78 CVE-2022-26211: Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function CloudACMunualUpdate, via the deviceMac and deviceName parameters. This vulner
nvd
CVE-2021-44247P2CRITICALCVSS 9.8v4.1.2cu.5050_b202005042022-02-04
CVE-2021-44247 [CRITICAL] CWE-77 CVE-2021-44247: Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_ Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.
nvd
CVE-2022-26214P2CRITICALCVSS 9.8v4.1.2cu.5050_b202005042022-03-15
CVE-2022-26214 [CRITICAL] CWE-78 CVE-2022-26214: Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary com
nvd
CVE-2021-46009P2CRITICALCVSS 9.8v5.9c.45772022-03-30
CVE-2021-46009 [CRITICAL] CWE-306 CVE-2021-46009: In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authenticati In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
nvd
CVE-2025-28035P2CRITICALCVSS 9.8v4.1.2cu.5247_b202111292025-04-22
CVE-2025-28035 [CRITICAL] CWE-78 CVE-2025-28035: TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vuln TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
nvd
CVE-2025-28034P2CRITICALCVSS 9.8v4.1.2cu.5247_b202111292025-04-22
CVE-2025-28034 [CRITICAL] CWE-78 CVE-2025-28034: TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102 TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.
nvd
CVE-2021-44620P2CRITICALCVSS 9.8≤ 4.1.2cu.5050_b202005042022-03-11
CVE-2021-44620 [CRITICAL] CWE-77 CVE-2021-44620: A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
nvd
CVE-2025-45787P3CRITICALCVSS 9.8v5.9c.15272025-05-08
CVE-2025-45787 [CRITICAL] CWE-787 CVE-2025-45787: TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFil TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.
nvd
CVE-2025-45789P3CRITICALCVSS 9.8v5.9c.15272025-05-08
CVE-2025-45789 [CRITICAL] CWE-787 CVE-2025-45789: TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParen TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.
nvd