Totolink A7000R Firmware vulnerabilities
35 known vulnerabilities affecting totolink/a7000r_firmware.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH21MEDIUM2
Vulnerabilities
Page 2 of 2
CVE-2022-37083P3HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37083 [HIGH] CWE-78 CVE-2022-37083: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function setDiagnosisCfg.
nvd
CVE-2022-37082P3HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37082 [HIGH] CWE-78 CVE-2022-37082: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the function NTPSyncWithHost.
nvd
CVE-2022-37081P3HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37081 [HIGH] CWE-78 CVE-2022-37081: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.
nvd
CVE-2022-37078P3HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37078 [HIGH] CWE-787 CVE-2022-37078: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at /setting/setLanguageCfg.
nvd
CVE-2025-63154P3HIGHCVSS 7.5v9.1.0u.6115_b202010222025-11-10
CVE-2025-63154 [HIGH] CWE-121 CVE-2025-63154: TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect p
TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2025-63462P3HIGHCVSS 7.5v9.1.0u.6115_b202010222025-10-31
CVE-2025-63462 [HIGH] CWE-121 CVE-2025-63462: Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff pa
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63461P3HIGHCVSS 7.5v9.1.0u.6115_b202010222025-10-31
CVE-2025-63461 [HIGH] CWE-121 CVE-2025-63461: Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g par
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63460P3HIGHCVSS 7.5v9.1.0u.6115_b202010222025-10-31
CVE-2025-63460 [HIGH] CWE-121 CVE-2025-63460: Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g par
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63459P3HIGHCVSS 7.5v9.1.0u.6115_b202010222025-10-31
CVE-2025-63459 [HIGH] CWE-121 CVE-2025-63459: Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g par
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63153P3HIGHCVSS 7.5v9.1.0u.6115_b202010222025-11-10
CVE-2025-63153 [HIGH] CWE-121 CVE-2025-63153: TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parame
TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2022-37084P3HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37084 [HIGH] CWE-787 CVE-2022-37084: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the sPort para
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the sPort parameter at the addEffect function.
nvd
CVE-2022-37075P3HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37075 [HIGH] CWE-787 CVE-2022-37075: TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip paramet
TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
nvd
CVE-2022-37080P3HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37080 [HIGH] CWE-787 CVE-2022-37080: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command pa
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command parameter at setting/setTracerouteCfg.
nvd
CVE-2023-45985P3HIGHCVSS 7.5v9.1.0u.6115_b202010222023-10-16
CVE-2023-45985 [HIGH] CWE-787 CVE-2023-45985: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2022-37077P3HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37077 [HIGH] CWE-787 CVE-2022-37077: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser parameter.
nvd
← Previous2 / 2