Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Filtered by product A3600r Firmware
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-34993 1 Totolink 2 A3600r, A3600r Firmware 2023-12-10 N/A 9.8 CRITICAL
Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.
CVE-2022-36455 1 Totolink 2 A3600r, A3600r Firmware 2023-12-10 N/A 7.8 HIGH
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
CVE-2022-29377 1 Totolink 2 A3600r, A3600r Firmware 2023-12-10 5.0 MEDIUM 7.5 HIGH
Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.
CVE-2022-25078 1 Totolink 1 A3600r Firmware 2023-12-10 7.5 HIGH 9.8 CRITICAL
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.