cbcvebase.

Totolink A3700R Firmware vulnerabilities

43 known vulnerabilities affecting totolink/a3700r_firmware.

Total CVEs
43
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL17HIGH19MEDIUM7

Vulnerabilities

Page 3 of 3
CVE-2025-3664P3MEDIUMCVSS 5.3v9.1.2u.5822_b202005132025-04-16
CVE-2025-3664 [MEDIUM] CWE-266 CVE-2025-3664: A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B2020051 A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor
nvd
CVE-2025-3675P3MEDIUMCVSS 5.3v9.1.2u.5822_b202005132025-04-16
CVE-2025-3675 [MEDIUM] CWE-266 CVE-2025-3675: A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. A A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-3674P3MEDIUMCVSS 5.3v9.1.2u.5822_b202005132025-04-16
CVE-2025-3674 [MEDIUM] CWE-266 CVE-2025-3674: A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
nvd