Totolink A3100R Firmware vulnerabilities
47 known vulnerabilities affecting totolink/a3100r_firmware.
Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
3
Severity breakdown
CRITICAL25HIGH20MEDIUM2
Vulnerabilities
Page 2 of 3
CVE-2025-45788P3CRITICALCVSS 9.8v5.9c.15272025-05-08
CVE-2025-45788 [CRITICAL] CWE-787 CVE-2025-45788: TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilte
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.
nvd
CVE-2024-42546P3CRITICALCVSS 9.8v4.1.2cu.5050_b202005042024-08-12
CVE-2024-42546 [CRITICAL] CWE-120 CVE-2024-42546: TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password paramete
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.
nvd
CVE-2022-29645P3CRITICALCVSS 9.8v4.1.2cu.5050_b20200504v4.1.2cu.5247_b202111292022-05-18
CVE-2022-29645 [CRITICAL] CWE-798 CVE-2022-29645: TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a har
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component /etc/shadow.sample.
nvd
CVE-2024-42547P3CRITICALCVSS 9.8v4.1.2cu.5050_b202005042024-08-12
CVE-2024-42547 [CRITICAL] CWE-120 CVE-2024-42547: TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host paramet
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
nvd
CVE-2025-45790P3CRITICALCVSS 9.8v5.9c.15272025-05-08
CVE-2025-45790 [CRITICAL] CWE-787 CVE-2025-45790: TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMac
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so.
nvd
CVE-2022-29639P3HIGHCVSS 8.1v4.1.2cu.5050_b20200504v4.1.2cu.5247_b202111292022-05-18
CVE-2022-29639 [HIGH] CVE-2022-29639: TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a com
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a command injection vulnerability via the magicid parameter in the function uci_cloudupdate_config.
nvd
CVE-2022-29644P3CRITICALCVSS 9.8v4.1.2cu.5050_b20200504v4.1.2cu.5247_b202111292022-05-18
CVE-2022-29644 [CRITICAL] CWE-798 CVE-2022-29644: TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a har
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in the component /web_cste/cgi-bin/product.ini.
nvd
CVE-2025-28256P3CRITICALCVSS 9.8v4.1.2cu.5247_b202111292025-03-28
CVE-2025-28256 [CRITICAL] CWE-78 CVE-2025-28256: An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary co
An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.
nvd
CVE-2021-46008P3HIGHCVSS 8.8v5.9c.45772022-03-30
CVE-2021-46008 [HIGH] CWE-798 CVE-2021-46008: In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official releas
In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.
nvd
CVE-2021-46010P3HIGHCVSS 8.8v5.9c.45772022-03-30
CVE-2021-46010 [HIGH] CWE-330 CVE-2021-46010: Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuratio
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
nvd
CVE-2022-28935P3HIGHCVSS 7.2v4.1.2cu.5050_b202005042022-07-06
CVE-2022-28935 [HIGH] CWE-77 CVE-2022-28935: Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2
Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B20200730, Totolink A3000RU V5.9c.5185_B20201128, Totolink A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability.
nvd
CVE-2025-28025P3HIGHCVSS 7.3v4.1.2cu.5247_b202111292025-04-23
CVE-2025-28025 [HIGH] CWE-120 CVE-2025-28025: TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128
TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.
nvd
CVE-2025-28028P3HIGHCVSS 7.3v4.1.2cu.5247_b202111292025-04-23
CVE-2025-28028 [HIGH] CWE-120 CVE-2025-28028: TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128
TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v5 parameter.
nvd
CVE-2025-28033P3HIGHCVSS 7.3v4.1.2cu.5247_b202111292025-04-22
CVE-2025-28033 [HIGH] CWE-121 CVE-2025-28033: TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpTo parameter.
nvd
CVE-2025-28032P3HIGHCVSS 7.3v4.1.2cu.5247_b202111292025-04-22
CVE-2025-28032 [HIGH] CWE-121 CVE-2025-28032: TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm parameter.
nvd
CVE-2021-46006P3MEDIUMCVSS 6.5v5.9c.45772022-03-30
CVE-2021-46006 [MEDIUM] CWE-306 CVE-2021-46006: In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated.
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.
nvd
CVE-2025-28029P3HIGHCVSS 7.3v4.1.2cu.5247_b202111292025-04-22
CVE-2025-28029 [HIGH] CWE-121 CVE-2025-28029: TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128
TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in cstecgi.cgi
nvd
CVE-2025-28026P3HIGHCVSS 7.3v4.1.2cu.5247_b202111292025-04-22
CVE-2025-28026 [HIGH] CWE-121 CVE-2025-28026: TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128
TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi.
nvd
CVE-2025-28027P3HIGHCVSS 7.3v4.1.2cu.5247_b202111292025-04-22
CVE-2025-28027 [HIGH] CWE-121 CVE-2025-28027: TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128
TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 was found to contain a buffer overflow vulnerability in downloadFile.cgi.
nvd
CVE-2022-29642P3HIGHCVSS 7.5v4.1.2cu.5050_b20200504v4.1.2cu.5247_b202111292022-05-18
CVE-2022-29642 [HIGH] CWE-787 CVE-2022-29642: TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a sta
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the url parameter in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd