Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Filtered by product A7100ru
Total 36 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-7095 1 Totolink 2 A7100ru, A7100ru Firmware 2024-04-11 10.0 HIGH 9.8 CRITICAL
A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248942 is the identifier assigned to this vulnerability.
CVE-2023-6906 1 Totolink 2 A7100ru, A7100ru Firmware 2024-04-11 10.0 HIGH 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in Totolink A7100RU 7.4cu.2313_B20191024. Affected is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag with the input ie8 leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248268. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-25395 1 Totolink 2 A7100ru, A7100ru Firmware 2024-03-08 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou parameter at /setting/delStaticDhcpRules.
CVE-2023-26848 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.
CVE-2023-27231 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.
CVE-2023-27229 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg.
CVE-2023-26978 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.
CVE-2023-27232 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg.
CVE-2023-33556 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.
CVE-2023-30054 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.
CVE-2023-27135 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg.
CVE-2023-30053 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
CVE-2022-46631 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.
CVE-2023-24184 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability.
CVE-2022-44844 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.
CVE-2022-44843 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.
CVE-2022-47853 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root shell through a specially constructed payload.
CVE-2023-24276 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.
CVE-2022-48125 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password parameter in the setting/setOpenVpnCertGenerationCfg function.
CVE-2023-24238 1 Totolink 2 A7100ru, A7100ru Firmware 2023-12-10 N/A 9.8 CRITICAL
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.