Vulnerabilities
Vulnerable Software
Totolink:  Security Vulnerabilities
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
CVSS Score
7.8
EPSS Score
0.01
Published
2022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser parameter.
CVSS Score
7.8
EPSS Score
0.003
Published
2022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at /setting/setLanguageCfg.
CVSS Score
7.8
EPSS Score
0.009
Published
2022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
CVSS Score
7.8
EPSS Score
0.012
Published
2022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command parameter at setting/setTracerouteCfg.
CVSS Score
7.8
EPSS Score
0.003
Published
2022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.
CVSS Score
7.8
EPSS Score
0.01
Published
2022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the function NTPSyncWithHost.
CVSS Score
7.8
EPSS Score
0.01
Published
2022-08-25
TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
CVSS Score
7.8
EPSS Score
0.003
Published
2022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
CVSS Score
7.8
EPSS Score
0.01
Published
2022-08-25
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.
CVSS Score
7.8
EPSS Score
0.011
Published
2022-08-25


Contact Us

Shodan ® - All rights reserved