cbcvebase.

Totolink A7100Ru Firmware vulnerabilities

37 known vulnerabilities affecting totolink/a7100ru_firmware.

Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL37

Vulnerabilities

Page 1 of 2
CVE-2023-7095P2CRITICALCVSS 9.8v7.4cu.2313_b201910242023-12-25
CVE-2023-7095 [CRITICAL] CWE-120 CVE-2023-7095: A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20 A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag leads to buffer overflow. The attack may be launched remotely. The expl
nvd
CVE-2022-28575P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-05-05
CVE-2022-28575 [CRITICAL] CWE-78 CVE-2022-28575: It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payload
nvd
CVE-2022-28578P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-05-05
CVE-2022-28578 [CRITICAL] CWE-78 CVE-2022-28578: It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOli It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
nvd
CVE-2022-28584P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-05-05
CVE-2022-28584 [CRITICAL] CWE-78 CVE-2022-28584: It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTO It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
nvd
CVE-2022-28583P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-05-05
CVE-2022-28583 [CRITICAL] CWE-78 CVE-2022-28583: It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOli It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
nvd
CVE-2022-28579P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-05-05
CVE-2022-28579 [CRITICAL] CWE-78 CVE-2022-28579: It is found that there is a command injection vulnerability in the setParentalRules interface in TOT It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
nvd
CVE-2022-28577P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-05-05
CVE-2022-28577 [CRITICAL] CWE-78 CVE-2022-28577: It is found that there is a command injection vulnerability in the delParentalRules interface in TOT It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
nvd
CVE-2022-28582P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-05-05
CVE-2022-28582 [CRITICAL] CWE-78 CVE-2022-28582: It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOT It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
nvd
CVE-2022-28581P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-05-05
CVE-2022-28581 [CRITICAL] CWE-78 CVE-2022-28581: It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in T It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
nvd
CVE-2022-28580P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-05-05
CVE-2022-28580 [CRITICAL] CWE-78 CVE-2022-28580: It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOT It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
nvd
CVE-2023-33556P2CRITICALCVSS 9.8v7.4cu.2313_b201910242023-06-07
CVE-2023-33556 [CRITICAL] CWE-77 CVE-2023-33556: TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.
nvd
CVE-2022-44843P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-11-25
CVE-2022-44843 [CRITICAL] CWE-78 CVE-2022-44843: TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.
nvd
CVE-2022-46631P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-12-15
CVE-2022-46631 [CRITICAL] CWE-78 CVE-2022-46631: TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.
nvd
CVE-2022-46634P2CRITICALCVSS 9.8v7.4cu.2313_b201910242022-12-15
CVE-2022-46634 [CRITICAL] CWE-78 CVE-2022-46634: TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.
nvd
CVE-2023-27229P2CRITICALCVSS 9.8v7.4cu.2313_b201910242023-03-28
CVE-2023-27229 [CRITICAL] CWE-77 CVE-2023-27229: TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg.
nvd
CVE-2023-27231P2CRITICALCVSS 9.8v7.4cu.2313_b201910242023-03-28
CVE-2023-27231 [CRITICAL] CWE-77 CVE-2023-27231: TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.
nvd
CVE-2022-48123P2CRITICALCVSS 9.8v7.4cu.2313_b201910242023-01-20
CVE-2022-48123 [CRITICAL] CWE-78 CVE-2022-48123: TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setting/delStaticDhcpRules function.
nvd
CVE-2022-48122P2CRITICALCVSS 9.8v7.4cu.2313_b201910242023-01-20
CVE-2022-48122 [CRITICAL] CWE-78 CVE-2022-48122: TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the setting/delStaticDhcpRules function.
nvd
CVE-2022-48126P2CRITICALCVSS 9.8v7.4cu.2313_b201910242023-01-20
CVE-2022-48126 [CRITICAL] CWE-78 CVE-2022-48126: TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the setting/setOpenVpnCertGenerationCfg function.
nvd
CVE-2022-48121P2CRITICALCVSS 9.8v7.4cu.2313_b201910242023-01-20
CVE-2022-48121 [CRITICAL] CWE-78 CVE-2022-48121: TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability v TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the setting/delStaticDhcpRules function.
nvd
Totolink A7100Ru Firmware vulnerabilities | cvebase