CVE-2025-44655
- EPSS 0.35%
- Published 21.07.2025 00:00:00
- Last modified 07.08.2025 17:58:19
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for inter...
CVE-2023-7095
- EPSS 14.24%
- Published 25.12.2023 01:15:08
- Last modified 21.11.2024 08:45:14
A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The mani...
CVE-2023-6906
- EPSS 0.12%
- Published 18.12.2023 04:15:51
- Last modified 21.11.2024 08:44:48
A vulnerability, which was classified as critical, was found in Totolink A7100RU 7.4cu.2313_B20191024. Affected is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the arg...
CVE-2023-33556
- EPSS 1.45%
- Published 07.06.2023 21:15:13
- Last modified 07.01.2025 15:15:08
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.
CVE-2023-30054
- EPSS 4.12%
- Published 05.05.2023 15:15:10
- Last modified 29.01.2025 18:15:45
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.
CVE-2023-30053
- EPSS 4.12%
- Published 05.05.2023 15:15:10
- Last modified 29.01.2025 18:15:45
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
CVE-2023-26978
- EPSS 1.45%
- Published 07.04.2023 04:15:41
- Last modified 12.02.2025 20:15:31
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.
CVE-2023-26848
- EPSS 1.45%
- Published 07.04.2023 03:15:07
- Last modified 12.02.2025 20:15:30
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.
CVE-2023-27232
- EPSS 1.58%
- Published 28.03.2023 23:15:09
- Last modified 18.02.2025 21:15:16
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg.
CVE-2023-27231
- EPSS 3.69%
- Published 28.03.2023 22:15:09
- Last modified 18.02.2025 21:15:15
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.