Vulnerabilities
Vulnerable Software
Totolink:  Security Vulnerabilities
It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
CVSS Score
9.8
EPSS Score
0.03
Published
2022-05-05
It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
CVSS Score
9.8
EPSS Score
0.03
Published
2022-05-05
It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
CVSS Score
9.8
EPSS Score
0.03
Published
2022-05-05
It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
CVSS Score
9.8
EPSS Score
0.03
Published
2022-05-05
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
CVSS Score
6.1
EPSS Score
0.006
Published
2022-05-02
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.
CVSS Score
7.5
EPSS Score
0.01
Published
2022-03-31
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.
CVSS Score
6.1
EPSS Score
0.006
Published
2022-03-31
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.
CVSS Score
6.5
EPSS Score
0.005
Published
2022-03-31
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
CVSS Score
8.8
EPSS Score
0.044
Published
2022-03-30
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.
CVSS Score
8.1
EPSS Score
0.017
Published
2022-03-30


Contact Us

Shodan ® - All rights reserved