VendorsTOTOLINKa3100r_firmware5.9c.4577
Vulnerabilities

TOTOLINK A3100R Firmware 4.1.2cu.5050 B20200504 5.9c.4577

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-46009
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
Published 2022-03-30 · Modified
10.0EPSS 0.125
CVE-2021-46010
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
Published 2022-03-30 · Modified
8.8EPSS 0.012
CVE-2021-46008
In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.
Published 2022-03-30 · Modified
8.8EPSS 0.009
CVE-2021-46006
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.
Published 2022-03-30 · Modified
6.5EPSS 0.055