Totolink X5000R Firmware vulnerabilities

70 known vulnerabilities affecting totolink/x5000r_firmware.

Total CVEs
70
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH38MEDIUM10

Vulnerabilities

Page 4 of 4
CVE-2022-27004CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-03-15
CVE-2022-27004 [CRITICAL] CWE-78 CVE-2022-27004: Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered t Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2022-27003CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-03-15
CVE-2022-27003 [CRITICAL] CWE-78 CVE-2022-27003: Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered t Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2021-45733CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-02-04
CVE-2021-45733 [CRITICAL] CWE-77 CVE-2021-45733: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability i TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.
nvd
CVE-2021-45738CRITICALCVSS 9.8v9.1.0u.6118_b202011022022-02-04
CVE-2021-45738 [CRITICAL] CWE-77 CVE-2021-45738: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability i TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.
nvd
CVE-2021-45741HIGHCVSS 7.5v9.1.0u.6118_b202011022022-02-04
CVE-2021-45741 [HIGH] CVE-2021-45741: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function se TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.
nvd
CVE-2021-45735HIGHCVSS 7.5v9.1.0u.6118_b202011022022-02-04
CVE-2021-45735 [HIGH] CWE-319 CVE-2021-45735: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication in TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.
nvd
CVE-2021-45736HIGHCVSS 7.5v9.1.0u.6118_b202011022022-02-04
CVE-2021-45736 [HIGH] CVE-2021-45736: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function se TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.
nvd
CVE-2021-45734HIGHCVSS 7.5v9.1.0u.6118_b202011022022-02-04
CVE-2021-45734 [HIGH] CVE-2021-45734: TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function se TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via the url parameter.
nvd
CVE-2021-27710CRITICALCVSS 9.8v9.1.0u.6118_b202011022021-04-14
CVE-2021-27710 [CRITICAL] CWE-78 CVE-2021-27710: Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "ip" pa
nvd
CVE-2021-27708CRITICALCVSS 9.8v9.1.0u.6118_b202011022021-04-14
CVE-2021-27708 [CRITICAL] CWE-78 CVE-2021-27708: Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "comman
nvd