Vulnerability index

Browse CVEs

1,039 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-35324EPSS 10% A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication. A720r Firmware No fix yet Fix from $2,3002021-08-05 CRITICAL 9.8 CVE-2021-35327 A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default cre… A720r Firmware No fix yet Fix from $2,3002021-08-05 HIGH 7.5 CVE-2021-35325EPSS 13% A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service… A720r Firmware No fix yet Fix from $1,9502021-08-05 HIGH 7.5 CVE-2021-35326 A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a craft… A720r Firmware No fix yet Fix from $1,9502021-08-05 CRITICAL 9.8 CVE-2021-27710EPSS 8% Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo… X5000r Firmware No fix yet Fix from $2,3002021-04-14 CRITICAL 9.8 CVE-2021-27708EPSS 8% Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo… X5000r Firmware No fix yet Fix from $2,3002021-04-14 MEDIUM 5.5 CVE-2020-27368 Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Para… A702r Firmware No fix yet Fix from $1,6002021-01-14 MEDIUM 6.5 CVE-2018-13313 In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contai… A3002ru Firmware No fix yet Fix from $1,6002020-02-24 CRITICAL 9.8 CVE-2018-13306 System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter. A3002ru Firmware No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13307 System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST paramet… A3002ru Firmware No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13314 System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter. A3002ru Firmware No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13316 System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter. A3002ru Firmware No fix yet Fix from $2,3002018-11-27 CRITICAL 9.8 CVE-2018-13311 System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter. A3002ru Firmware Mitigation only Fix from $2,3002018-11-26 CRITICAL 9.8 CVE-2018-13315 Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthent… A3002ru Firmware No fix yet Fix from $2,3002018-11-26 MEDIUM 6.1 CVE-2018-13308 Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phra… A3002ru Firmware No fix yet Fix from $1,6002018-11-26 MEDIUM 6.1 CVE-2018-13309 Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password. A3002ru Firmware No fix yet Fix from $1,6002018-11-26 MEDIUM 6.1 CVE-2018-13310 Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username. A3002ru Firmware Mitigation only Fix from $1,6002018-11-26 MEDIUM 6.1 CVE-2018-13312 Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input you… A3002ru Firmware No fix yet Fix from $1,6002018-11-26 MEDIUM 6.1 CVE-2018-13317 Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making … A3002ru Firmware No fix yet Fix from $1,6002018-11-26