CVE-2021-46006Medium· 6.5▾ SunlitIn Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 1.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.2%
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.
a3100r_firmware = 5.9c.4577Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-46009Critical· 9.8In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication
CVE-2021-46010High· 8.8Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration
CVE-2021-46008High· 8.8In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware
CVE-2021-44620Critical· 9.8A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
CVE-2022-29641High· 7.5TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules
CVE-2021-46007Critical· 9.8totolink a3100r V5.9c.4577 is vulnerable to os command injection