Totolink A3100R Firmware vulnerabilities
47 known vulnerabilities affecting totolink/a3100r_firmware.
Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
3
Severity breakdown
CRITICAL25HIGH20MEDIUM2
Vulnerabilities
Page 3 of 3
CVE-2021-44246P3HIGHCVSS 7.5v4.1.2cu.5050_b202005042022-02-04
CVE-2021-44246 [HIGH] CVE-2021-44246: Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain a stack overflow in the function setNoticeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IpTo parameter.
nvd
CVE-2024-36650P3HIGHCVSS 7.5v4.1.2cu.5247_b202111292024-06-11
CVE-2024-36650 [HIGH] CWE-120 CVE-2024-36650: TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cg
TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/lib/cste_modules/system.so`, the length of the user input string `NoticeUrl` is not checked. This can lead to a buffer overflow, allowing attackers to construct malicious HTTP or MQTT requests to cause a denial-of
nvd
CVE-2022-29640P3HIGHCVSS 7.5v4.1.2cu.5050_b20200504v4.1.2cu.5247_b202111292022-05-18
CVE-2022-29640 [HIGH] CWE-787 CVE-2022-29640: TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a sta
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the comment parameter in the function setPortForwardRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2022-29643P3HIGHCVSS 7.5v4.1.2cu.5050_b20200504v4.1.2cu.5247_b202111292022-05-18
CVE-2022-29643 [HIGH] CWE-787 CVE-2022-29643: TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a sta
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the macAddress parameter in the function setMacQos. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2022-29638P3HIGHCVSS 7.5v4.1.2cu.5050_b20200504v4.1.2cu.5247_b202111292022-05-18
CVE-2022-29638 [HIGH] CWE-787 CVE-2022-29638: TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a sta
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the comment parameter in the function setIpQosRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2022-29641P3HIGHCVSS 7.5v4.1.2cu.5050_b20200504v4.1.2cu.5247_b202111292022-05-18
CVE-2022-29641 [HIGH] CWE-787 CVE-2022-29641: TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a sta
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2022-29646P4MEDIUMCVSS 5.3v4.1.2cu.5050_b20200504v4.1.2cu.5247_b202111292022-05-18
CVE-2022-29646 [MEDIUM] CWE-668 CVE-2022-29646: An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allow
An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtain sensitive information via a crafted web request.
nvd
← Previous3 / 3