Totolink

X5000r Firmware

70 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 45.94%
  • Veröffentlicht 15.03.2022 22:15:15
  • Zuletzt bearbeitet 21.11.2024 06:54:59

Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbit...

Exploit
  • EPSS 31.51%
  • Veröffentlicht 15.03.2022 22:15:14
  • Zuletzt bearbeitet 21.11.2024 06:53:36

Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 04.02.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:59

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.

Exploit
  • EPSS 25.81%
  • Veröffentlicht 04.02.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:59

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 04.02.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:58

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.

Exploit
  • EPSS 0.25%
  • Veröffentlicht 04.02.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:58

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 04.02.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:58

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via the url parameter.

Exploit
  • EPSS 25.81%
  • Veröffentlicht 04.02.2022 02:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:58

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.

Exploit
  • EPSS 20.15%
  • Veröffentlicht 14.04.2021 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:58:28

Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs ...

Exploit
  • EPSS 20.15%
  • Veröffentlicht 14.04.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:58:27

Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs ...