CVE-2022-29641High· 7.5▾ TwilightTOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Den…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.3%
TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
a3100r_firmware = 4.1.2cu.5050_b20200504a3100r_firmware = 4.1.2cu.5247_b20211129Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-46010High· 8.8Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration
CVE-2021-46009Critical· 9.8In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication
CVE-2021-46008High· 8.8In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware
CVE-2021-46006Medium· 6.5In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated
CVE-2021-44620Critical· 9.8A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
CVE-2026-26731High· 8.8TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.