VYPR

A3100r Firmware

by Totolink

CVEs (37)

  • CVE-2022-25077CriFeb 24, 2022
    risk 0.66cvss 9.8epss 0.33

    TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2021-46009CriMar 30, 2022
    risk 0.65cvss 9.8epss 0.12

    In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

  • CVE-2025-45790CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so.

  • CVE-2025-45789CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.

  • CVE-2025-45788CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.

  • CVE-2025-45787CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.

  • CVE-2025-28036CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

  • CVE-2025-28035CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

  • CVE-2025-28256CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.

  • CVE-2024-42547CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.

  • CVE-2024-42546CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.

  • CVE-2022-29645CriMay 18, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component /etc/shadow.sample.

  • CVE-2022-29644CriMay 18, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in the component /web_cste/cgi-bin/product.ini.

  • CVE-2022-26214CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26211CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26208CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26206CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2021-44620CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

  • CVE-2021-44247CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom…

  • CVE-2024-7157HigJul 28, 2024
    risk 0.58cvss 8.8epss 0.07

    A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been classified as critical. This affects the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_host leads to buffer overflow. It is…

Page 1 of 2