Skip to main content

Vendor/product archive

totolink / a720r CVEs

Beta · best-effort

28 CVEs tagged to totolink / a720r8 Critical, 10 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2025-60685

Published Nov 13, 2025

A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file u…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60683

Published Nov 13, 2025

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handl…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60682

Published Nov 13, 2025

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4271

Published May 5, 2025

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/cstec…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-4270

Published May 5, 2025

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component C…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
35.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-4269

Published May 5, 2025

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi of the component Lo…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
35.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-4268

Published May 5, 2025

A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi. The manipulation…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-8869

Published Sep 15, 2024

A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It is possible…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-45742

Published Feb 4, 2022

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45740

Published Feb 4, 2022

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45739

Published Feb 4, 2022

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45737

Published Feb 4, 2022

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35327

Published Aug 5, 2021

A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST re…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-35326

Published Aug 5, 2021

A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a crafted HTTP request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2