CVE-2025-51452
- EPSS 0.13%
- Published 13.08.2025 00:00:00
- Last modified 14.08.2025 14:15:33
In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
CVE-2024-7213
- EPSS 0.53%
- Published 30.07.2024 03:15:01
- Last modified 21.11.2024 09:51:06
A vulnerability, which was classified as critical, was found in TOTOLINK A7000R 9.1.0u.6268_B20220504. Affected is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to buffer overflow. It is possi...
CVE-2024-7212
- EPSS 0.56%
- Published 30.07.2024 02:15:08
- Last modified 21.11.2024 09:51:06
A vulnerability, which was classified as critical, has been found in TOTOLINK A7000R 9.1.0u.6268_B20220504. This issue affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow...
CVE-2024-28640
- EPSS 0.5%
- Published 16.03.2024 06:15:14
- Last modified 27.06.2025 14:26:44
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.
CVE-2024-28639
- EPSS 3.45%
- Published 16.03.2024 06:15:14
- Last modified 26.03.2025 15:15:49
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.
CVE-2023-49418
- EPSS 0.12%
- Published 11.12.2023 14:15:31
- Last modified 21.11.2024 08:33:22
TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules.
CVE-2023-49417
- EPSS 0.11%
- Published 11.12.2023 14:15:31
- Last modified 27.05.2025 15:15:31
TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.
CVE-2023-45985
- EPSS 0.35%
- Published 16.10.2023 18:15:16
- Last modified 21.11.2024 08:27:42
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST ...
CVE-2023-45984
- EPSS 0.21%
- Published 16.10.2023 18:15:16
- Last modified 21.11.2024 08:27:42
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.
CVE-2023-36950
- EPSS 0.91%
- Published 16.10.2023 06:15:10
- Last modified 21.11.2024 08:10:58
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.