Totolink A7000R Firmware vulnerabilities
35 known vulnerabilities affecting totolink/a7000r_firmware.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH20MEDIUM4
Vulnerabilities
Page 2 of 2
CVE-2023-45985HIGHCVSS 7.5v9.1.0u.6115_b202010222023-10-16
CVE-2023-45985 [HIGH] CWE-787 CVE-2023-45985: TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2022-32993CRITICALCVSS 9.8v4.1cu.41342022-08-29
CVE-2022-32993 [CRITICAL] CVE-2022-32993: TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSet
TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
nvd
CVE-2022-37082HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37082 [HIGH] CWE-78 CVE-2022-37082: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the function NTPSyncWithHost.
nvd
CVE-2022-37076HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37076 [HIGH] CWE-78 CVE-2022-37076: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
nvd
CVE-2022-37077HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37077 [HIGH] CWE-787 CVE-2022-37077: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser parameter.
nvd
CVE-2022-37079HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37079 [HIGH] CWE-78 CVE-2022-37079: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
nvd
CVE-2022-37084HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37084 [HIGH] CWE-787 CVE-2022-37084: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the sPort para
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the sPort parameter at the addEffect function.
nvd
CVE-2022-37075HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37075 [HIGH] CWE-787 CVE-2022-37075: TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip paramet
TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
nvd
CVE-2022-37083HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37083 [HIGH] CWE-78 CVE-2022-37083: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function setDiagnosisCfg.
nvd
CVE-2022-37078HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37078 [HIGH] CWE-787 CVE-2022-37078: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at /setting/setLanguageCfg.
nvd
CVE-2022-37080HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37080 [HIGH] CWE-787 CVE-2022-37080: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command pa
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command parameter at setting/setTracerouteCfg.
nvd
CVE-2022-37081HIGHCVSS 7.8v9.1.0u.6115_b202010222022-08-25
CVE-2022-37081 [HIGH] CWE-78 CVE-2022-37081: TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability v
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.
nvd
CVE-2022-27005CRITICALCVSS 9.8v9.1.0u.6115_b202010222022-03-15
CVE-2022-27005 [CRITICAL] CWE-78 CVE-2022-27005: Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered t
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2022-27004CRITICALCVSS 9.8v9.1.0u.6115_b202010222022-03-15
CVE-2022-27004 [CRITICAL] CWE-78 CVE-2022-27004: Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered t
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2022-27003CRITICALCVSS 9.8v9.1.0u.6115_b202010222022-03-15
CVE-2022-27003 [CRITICAL] CWE-78 CVE-2022-27003: Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered t
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
← Previous2 / 2