Vulnerability index

Browse CVEs

1,082 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

A3002r Firmware MEDIUM 6.1
CVE-2021-34207

Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScr…

No fix yet
Fix from $1,600 2021-08-20
A3002r Firmware MEDIUM 6.1
CVE-2021-34215

Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary Jav…

No fix yet
Fix from $1,600 2021-08-20
A3002r Firmware MEDIUM 6.1
CVE-2021-34220

Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary …

No fix yet
Fix from $1,600 2021-08-20
A3002r Firmware MEDIUM 6.1
CVE-2021-34223

Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary Ja…

No fix yet
Fix from $1,600 2021-08-20
A3002r Firmware MEDIUM 6.1
CVE-2021-34228EPSS 29%

Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitra…

No fix yet
Fix from $1,600 2021-08-20
A3002r Firmware MEDIUM 5.3
CVE-2021-34218

Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile…

No fix yet
Fix from $1,600 2021-08-20
A720r Firmware CRITICAL 9.8
CVE-2021-35324EPSS 10%

A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication.

No fix yet
Fix from $2,300 2021-08-05
A720r Firmware CRITICAL 9.8
CVE-2021-35327

A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default cre…

No fix yet
Fix from $2,300 2021-08-05
A720r Firmware HIGH 7.5
CVE-2021-35325EPSS 13%

A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service…

No fix yet
Fix from $1,950 2021-08-05
A720r Firmware HIGH 7.5
CVE-2021-35326

A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a craft…

No fix yet
Fix from $1,950 2021-08-05
X5000r Firmware CRITICAL 9.8
CVE-2021-27710EPSS 8%

Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo…

No fix yet
Fix from $2,300 2021-04-14
X5000r Firmware CRITICAL 9.8
CVE-2021-27708EPSS 8%

Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo…

No fix yet
Fix from $2,300 2021-04-14
A702r Firmware MEDIUM 5.5
CVE-2020-27368

Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Para…

No fix yet
Fix from $1,600 2021-01-14
A3002r Firmware HIGH 8.8
CVE-2020-25499

TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality…

Fix: 1.0.0-b20201028.1743 / 1.0.0-b20201103.1713+
Fix from $1,950 2020-12-09
A850r V1 Firmware CRITICAL 9.8
CVE-2015-9551

An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Executio…

Fix: 1.0.1-b20150707.1612 / 1.1-b20150708.1559+
Fix from $2,300 2020-11-24
A850r V1 Firmware HIGH 7.5
CVE-2015-9550

An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xas…

Fix: 1.0.1-b20150707.1612 / 1.1-b20150708.1559+
Fix from $1,950 2020-11-24
A3002ru Firmware MEDIUM 6.5
CVE-2018-13313

In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contai…

No fix yet
Fix from $1,600 2020-02-24
A3002ru Firmware HIGH 8.8
CVE-2019-19824EPSS 25%

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/for…

Fix: after 4.0.0
Fix from $1,950 2020-01-27
A3002ru Firmware HIGH 7.5
CVE-2019-19822EPSS 9%

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configurati…

Fix: after 2019-12-12
Fix from $1,950 2020-01-27
A3002ru Firmware HIGH 7.5
CVE-2019-19823EPSS 6%

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash …

Fix: after 2019-12-12
Fix from $1,950 2020-01-27
A3002ru Firmware CRITICAL 9.8
CVE-2019-19825EPSS 30%

On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin…

Fix: after 4.0.0
Fix from $2,300 2020-01-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13306

System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.

No fix yet
Fix from $2,300 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13307

System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST paramet…

No fix yet
Fix from $2,300 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13314

System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.

No fix yet
Fix from $2,300 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13316

System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter.

No fix yet
Fix from $2,300 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13311

System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.

Mitigation only
Fix from $2,300 2018-11-26
A3002ru Firmware CRITICAL 9.8
CVE-2018-13315

Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthent…

No fix yet
Fix from $2,300 2018-11-26
A3002ru Firmware MEDIUM 6.1
CVE-2018-13308

Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phra…

No fix yet
Fix from $1,600 2018-11-26
A3002ru Firmware MEDIUM 6.1
CVE-2018-13309

Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.

No fix yet
Fix from $1,600 2018-11-26
A3002ru Firmware MEDIUM 6.1
CVE-2018-13310

Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.

Mitigation only
Fix from $1,600 2018-11-26