CVE-2024-8869
- EPSS 1.68%
- Veröffentlicht 15.09.2024 11:15:13
- Zuletzt bearbeitet 20.09.2024 16:59:22
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It is possible to launch the attack remotely. The complexity of an attack is rather hi...
CVE-2023-23064
- EPSS 0.7%
- Veröffentlicht 17.02.2023 22:15:14
- Zuletzt bearbeitet 18.03.2025 20:15:17
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
CVE-2022-38535
- EPSS 1.72%
- Veröffentlicht 15.09.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 07:16:37
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function.
CVE-2022-38534
- EPSS 1.72%
- Veröffentlicht 15.09.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 07:16:37
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function.
CVE-2022-36610
- EPSS 0.29%
- Veröffentlicht 29.08.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 07:13:24
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36456
- EPSS 1.1%
- Veröffentlicht 25.08.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 07:13:03
TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
CVE-2021-43662
- EPSS 0.55%
- Veröffentlicht 31.03.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:34
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.
- EPSS 3.07%
- Veröffentlicht 04.02.2022 02:15:08
- Zuletzt bearbeitet 21.11.2024 06:32:59
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
CVE-2021-45740
- EPSS 1.36%
- Veröffentlicht 04.02.2022 02:15:08
- Zuletzt bearbeitet 21.11.2024 06:32:59
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the pin parameter.
CVE-2021-45739
- EPSS 1.18%
- Veröffentlicht 04.02.2022 02:15:08
- Zuletzt bearbeitet 21.11.2024 06:32:59
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.