CVE-2021-45735
- EPSS 0.25%
- Published 04.02.2022 02:15:08
- Last modified 21.11.2024 06:32:58
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.
CVE-2021-45734
- EPSS 0.43%
- Published 04.02.2022 02:15:08
- Last modified 21.11.2024 06:32:58
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via the url parameter.
- EPSS 25.81%
- Published 04.02.2022 02:15:08
- Last modified 21.11.2024 06:32:58
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.
- EPSS 20.15%
- Published 14.04.2021 18:15:14
- Last modified 21.11.2024 05:58:28
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs ...
- EPSS 20.15%
- Published 14.04.2021 16:15:14
- Last modified 21.11.2024 05:58:27
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs ...