VendorsTOTOLINKa3600r_firmwareall versions
Vulnerabilities

TOTOLINK A3600R Firmware 4.1.2cu.5182 B20201102

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2026-5020
Totolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection
Published 2026-03-29 · Analyzed
9.8EPSS 0.037
CVE-2022-25078
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
Published 2022-02-22 · Modified
9.8EPSS 0.032
CVE-2026-31027
TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary code execution or denial of service.
Published 2026-04-01 · Analyzed
9.8EPSS 0.016
CVE-2022-34993
Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.
Published 2022-08-04 · Modified
9.8EPSS 0.010
CVE-2024-7174
TOTOLINK A3600R cstecgi.cgi setdeviceName buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.012
CVE-2024-7177
TOTOLINK A3600R cstecgi.cgi setLanguageCfg buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.012
CVE-2024-7187
TOTOLINK A3600R cstecgi.cgi UploadCustomModule buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.012
CVE-2024-7178
TOTOLINK A3600R cstecgi.cgi setMacQos buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.011
CVE-2024-7186
TOTOLINK A3600R cstecgi.cgi setWiFiAclAddConfig buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.011
CVE-2024-7185
TOTOLINK A3600R cstecgi.cgi setWebWlanIdx buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.011
CVE-2024-7184
TOTOLINK A3600R cstecgi.cgi setUrlFilterRules buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.011
CVE-2024-7183
TOTOLINK A3600R cstecgi.cgi setUploadSetting buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.011
CVE-2024-7182
TOTOLINK A3600R cstecgi.cgi setUpgradeFW buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.011
CVE-2024-7180
TOTOLINK A3600R cstecgi.cgi setPortForwardRules buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.011
CVE-2024-7179
TOTOLINK A3600R cstecgi.cgi setParentalRules buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.011
CVE-2024-7176
TOTOLINK A3600R cstecgi.cgi setIpQosRules buffer overflow
Published 2024-07-29 · Modified
9.0EPSS 0.011
CVE-2024-7173
TOTOLINK A3600R cstecgi.cgi loginauth buffer overflow
Published 2024-07-28 · Modified
9.0EPSS 0.011
CVE-2024-7172
TOTOLINK A3600R getSaveConfig buffer overflow
Published 2024-07-28 · Modified
9.0EPSS 0.011
CVE-2026-1686
Totolink A3600R app.so setAppEasyWizardConfig buffer overflow
Published 2026-01-30 · Analyzed
9.0EPSS 0.007
CVE-2024-7181
TOTOLINK A3600R cstecgi.cgi setTelnetCfg command injection
Published 2024-07-29 · Modified
8.8EPSS 0.031
CVE-2024-7175
TOTOLINK A3600R cstecgi.cgi setDiagnosisCfg os command injection
Published 2024-07-29 · Modified
8.8EPSS 0.031
CVE-2024-7171
TOTOLINK A3600R cstecgi.cgi NTPSyncWithHost os command injection
Published 2024-07-28 · Modified
8.8EPSS 0.031
CVE-2024-7159
TOTOLINK A3600R Telnet Service product.ini hard-coded password
Published 2024-07-28 · Modified
8.8EPSS 0.006
CVE-2022-36455
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
Published 2022-08-25 · Modified
7.8EPSS 0.010
CVE-2022-29377
Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.
Published 2022-05-24 · Modified
7.5EPSS 0.011