VulnSea

a3100r_firmware vulnerabilities

CVEs whose affected-version data names the a3100r_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2022-29641High· 7.5
4y ago

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Den…

Twilighttotolink · a3100r_firmwareEPSS 1.2%via NVD
CVE-2021-46010High· 8.8
4y ago

Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration

Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.

Twilighttotolink · a3100r_firmwareEPSS 1.2%via NVD
CVE-2021-46009Critical· 9.8
4y ago

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

Midnighttotolink · a3100r_firmwareEPSS 13%via NVD
CVE-2021-46008High· 8.8
4y ago

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function tur…

Twilighttotolink · a3100r_firmwareEPSS 0.92%via NVD
CVE-2021-46006Medium· 6.5
4y ago

In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated

In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.

Sunlittotolink · a3100r_firmwareEPSS 5.5%via NVD
CVE-2021-44620Critical· 9.8
4y ago

A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

Midnighttotolink · a3100r_firmwareEPSS 1.4%via NVD
a3100r_firmware vulnerabilities (CVEs) · VulnSea