Totolink A3700R Firmware vulnerabilities
43 known vulnerabilities affecting totolink/a3700r_firmware.
Total CVEs
43
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL17HIGH19MEDIUM7
Vulnerabilities
Page 2 of 3
CVE-2024-37631P3HIGHCVSS 8.8v9.1.2u.6165_202110122024-06-13
CVE-2024-37631 [HIGH] CWE-121 CVE-2024-37631: TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parame
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.
nvd
CVE-2023-43141P3CRITICALCVSS 9.8v9.1.2u.6134_b202012022023-09-25
CVE-2023-43141 [CRITICAL] CWE-284 CVE-2023-43141: TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Contr
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
nvd
CVE-2024-37640P3HIGHCVSS 8.8v9.1.2u.6165_202110122024-06-14
CVE-2024-37640 [HIGH] CWE-121 CVE-2024-37640: TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the f
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.
nvd
CVE-2024-37633P3HIGHCVSS 8.8v9.1.2u.6165_202110122024-06-13
CVE-2024-37633 [HIGH] CWE-121 CVE-2024-37633: TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the fun
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg
nvd
CVE-2024-37639P3HIGHCVSS 8.8v9.1.2u.6165_202110122024-06-14
CVE-2024-37639 [HIGH] CWE-121 CVE-2024-37639: TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the fu
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.
nvd
CVE-2024-7154P3HIGHCVSS 7.5v9.1.2u.5822_b202005132024-07-28
CVE-2024-7154 [HIGH] CWE-284 CVE-2024-7154: A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B2020
A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file /wizard.html of the component Password Reset Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may
nvd
CVE-2022-36461P3HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36461 [HIGH] CWE-78 CVE-2022-36461: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability v
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
nvd
CVE-2022-36460P3HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36460 [HIGH] CWE-78 CVE-2022-36460: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability v
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
nvd
CVE-2022-36458P3HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36458 [HIGH] CWE-78 CVE-2022-36458: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability v
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.
nvd
CVE-2022-36459P3HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36459 [HIGH] CWE-78 CVE-2022-36459: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability v
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.
nvd
CVE-2022-36464P3HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36464 [HIGH] CWE-787 CVE-2022-36464: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort para
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.
nvd
CVE-2022-36463P3HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36463 [HIGH] CWE-787 CVE-2022-36463: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command pa
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.
nvd
CVE-2022-36466P3HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36466 [HIGH] CWE-787 CVE-2022-36466: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip paramet
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
nvd
CVE-2022-36462P3HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36462 [HIGH] CWE-787 CVE-2022-36462: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the lang param
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.
nvd
CVE-2022-36465P3HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36465 [HIGH] CWE-787 CVE-2022-36465: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.
nvd
CVE-2023-48192P3HIGHCVSS 7.8v9.1.2u.6134_b202012022023-11-20
CVE-2023-48192 [HIGH] CWE-94 CVE-2023-48192: An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary cod
An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.
nvd
CVE-2025-3668P3MEDIUMCVSS 5.3v9.1.2u.5822_b202005132025-04-16
CVE-2025-3668 [MEDIUM] CWE-266 CVE-2025-3668: A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor
nvd
CVE-2025-3666P3MEDIUMCVSS 5.3v9.1.2u.5822_b202005132025-04-16
CVE-2025-3666 [MEDIUM] CWE-266 CVE-2025-3666: A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affec
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacte
nvd
CVE-2025-3667P3MEDIUMCVSS 5.3v9.1.2u.5822_b202005132025-04-16
CVE-2025-3667 [MEDIUM] CWE-266 CVE-2025-3667: A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critic
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was c
nvd
CVE-2025-3665P3MEDIUMCVSS 5.3v9.1.2u.5822_b202005132025-04-16
CVE-2025-3665 [MEDIUM] CWE-266 CVE-2025-3665: A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical.
A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The ven
nvd