Totolink A3700R Firmware vulnerabilities
43 known vulnerabilities affecting totolink/a3700r_firmware.
Total CVEs
43
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH15MEDIUM11
Vulnerabilities
Page 2 of 3
CVE-2024-37631HIGHCVSS 8.8v9.1.2u.6165_202110122024-06-13
CVE-2024-37631 [HIGH] CWE-121 CVE-2024-37631: TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parame
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.
nvd
CVE-2024-37633HIGHCVSS 8.8v9.1.2u.6165_202110122024-06-13
CVE-2024-37633 [HIGH] CWE-121 CVE-2024-37633: TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the fun
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg
nvd
CVE-2024-22660CRITICALCVSS 9.8v9.1.2u.6165_202110122024-01-23
CVE-2024-22660 [CRITICAL] CWE-787 CVE-2024-22660: TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg
nvd
CVE-2024-22662CRITICALCVSS 9.8v9.1.2u.6165_202110122024-01-23
CVE-2024-22662 [CRITICAL] CWE-787 CVE-2024-22662: TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules
TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules
nvd
CVE-2024-22663CRITICALCVSS 9.8v9.1.2u.6165_202110122024-01-23
CVE-2024-22663 [CRITICAL] CWE-77 CVE-2024-22663: TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
nvd
CVE-2023-52031CRITICALCVSS 9.8v9.1.2u.5822_b202005132024-01-11
CVE-2023-52031 [CRITICAL] CVE-2023-52031: TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vu
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function.
nvd
CVE-2023-52029CRITICALCVSS 9.8v9.1.2u.5822_b202005132024-01-11
CVE-2023-52029 [CRITICAL] CWE-78 CVE-2023-52029: TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vu
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setDiagnosisCfg function.
nvd
CVE-2023-52028CRITICALCVSS 9.8v9.1.2u.5822_b202005132024-01-11
CVE-2023-52028 [CRITICAL] CWE-78 CVE-2023-52028: TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vu
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.
nvd
CVE-2023-52027CRITICALCVSS 9.8v9.1.2u.5822_b202005132024-01-11
CVE-2023-52027 [CRITICAL] CWE-77 CVE-2023-52027: TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vu
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.
nvd
CVE-2023-52030CRITICALCVSS 9.8v9.1.2u.5822_b202005132024-01-11
CVE-2023-52030 [CRITICAL] CWE-250 CVE-2023-52030: TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vu
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.
nvd
CVE-2023-50147CRITICALCVSS 9.8v9.1.2u.5822_b202005132023-12-22
CVE-2023-50147 [CRITICAL] CWE-78 CVE-2023-50147: There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi
There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513.
nvd
CVE-2023-48192HIGHCVSS 7.8v9.1.2u.6134_b202012022023-11-20
CVE-2023-48192 [HIGH] CWE-94 CVE-2023-48192: An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary cod
An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.
nvd
CVE-2023-46574CRITICALCVSS 9.8PoCv9.1.2u.6165_202110122023-10-25
CVE-2023-46574 [CRITICAL] CWE-77 CVE-2023-46574: An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary cod
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
nvd
CVE-2023-43141CRITICALCVSS 9.8v9.1.2u.6134_b202012022023-09-25
CVE-2023-43141 [CRITICAL] CWE-284 CVE-2023-43141: TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Contr
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
nvd
CVE-2022-36458HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36458 [HIGH] CWE-78 CVE-2022-36458: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability v
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.
nvd
CVE-2022-36465HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36465 [HIGH] CWE-787 CVE-2022-36465: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.
nvd
CVE-2022-36463HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36463 [HIGH] CWE-787 CVE-2022-36463: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command pa
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.
nvd
CVE-2022-36466HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36466 [HIGH] CWE-787 CVE-2022-36466: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip paramet
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
nvd
CVE-2022-36461HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36461 [HIGH] CWE-78 CVE-2022-36461: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability v
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
nvd
CVE-2022-36460HIGHCVSS 7.8v9.1.2u.6134_b202012022022-08-25
CVE-2022-36460 [HIGH] CWE-78 CVE-2022-36460: TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability v
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
nvd