CVE-2021-46007Critical· 9.8▾ Midnighttotolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.6%
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.
ar3100r_firmware = 5.9c.4577Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-46010High· 8.8Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration
CVE-2021-46009Critical· 9.8In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication
CVE-2021-46008High· 8.8In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware
CVE-2021-46006Medium· 6.5In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated
CVE-2021-44620Critical· 9.8A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
CVE-2026-91853High· 7.4A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224