VendorsTOTOLINKa3700r_firmwareall versions
Vulnerabilities

TOTOLINK A3700R Firmware 9.1.2u.6134 B20201202

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2023-46574
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
Published 2023-10-24 · Modified
9.8EPSS 0.654
CVE-2024-22663
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
Published 2024-01-23 · Modified
9.8EPSS 0.017
CVE-2023-52027
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.
Published 2024-01-11 · Modified
9.8EPSS 0.017
CVE-2023-52028
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.017
CVE-2023-52029
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setDiagnosisCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.017
CVE-2023-52031
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function.
Published 2024-01-11 · Modified
9.8EPSS 0.015
CVE-2023-52030
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.015
CVE-2023-50147
There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513.
Published 2023-12-22 · Modified
9.8EPSS 0.012
CVE-2024-22662
TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules
Published 2024-01-23 · Modified
9.8EPSS 0.009
CVE-2024-22660
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg
Published 2024-01-23 · Modified
9.8EPSS 0.009
CVE-2024-37637
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.
Published 2024-06-14 · Analyzed
9.8EPSS 0.007
CVE-2024-37634
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.
Published 2024-06-13 · Analyzed
9.8EPSS 0.007
CVE-2024-42545
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.
Published 2024-08-12 · Modified
9.8EPSS 0.007
CVE-2024-37635
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg
Published 2024-06-13 · Modified
9.8EPSS 0.007
CVE-2024-42543
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
Published 2024-08-12 · Modified
9.8EPSS 0.007
CVE-2023-43141
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
Published 2023-09-25 · Modified
9.8EPSS 0.007
CVE-2024-37632
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .
Published 2024-06-13 · Modified
9.8EPSS 0.006
CVE-2026-1143
TOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg buffer overflow
Published 2026-01-19 · Analyzed
9.0EPSS 0.007
CVE-2024-7160
TOTOLINK A3700R cstecgi.cgi setWanCfg command injection
Published 2024-07-28 · Modified
8.8EPSS 0.030
CVE-2024-37640
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.
Published 2024-06-14 · Analyzed
8.8EPSS 0.006
CVE-2024-37633
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg
Published 2024-06-13 · Analyzed
8.8EPSS 0.006
CVE-2024-37631
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.
Published 2024-06-13 · Analyzed
8.8EPSS 0.006
CVE-2024-37639
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.
Published 2024-06-14 · Analyzed
8.8EPSS 0.006
CVE-2025-3663
TOTOLINK A3700R Password cstecgi.cgi setWiFiEasyGuestCfg access control
Published 2025-04-16 · Analyzed
8.2EPSS 0.113
CVE-2022-36461
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.012
CVE-2022-36458
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.010
CVE-2022-36459
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.
Published 2022-08-25 · Modified
7.8EPSS 0.010
CVE-2022-36460
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
Published 2022-08-25 · Modified
7.8EPSS 0.010
CVE-2022-36464
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.
Published 2022-08-25 · Modified
7.8EPSS 0.003
CVE-2022-36465
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.
Published 2022-08-25 · Modified
7.8EPSS 0.003
CVE-2023-48192
An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.
Published 2023-11-20 · Modified
7.8EPSS 0.003
CVE-2022-36463
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.003
CVE-2022-36466
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.003
CVE-2022-36462
TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.
Published 2022-08-25 · Modified
7.8EPSS 0.003
CVE-2024-7156
TOTOLINK A3700R apmib Configuration ExportSettings.sh information disclosure
Published 2024-07-28 · Modified
7.5EPSS 0.133
CVE-2024-7154
TOTOLINK A3700R Password Reset wizard.html access control
Published 2024-07-28 · Modified
7.5EPSS 0.004
CVE-2025-3668
TOTOLINK A3700R cstecgi.cgi setScheduleCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.014
CVE-2025-3667
TOTOLINK A3700R cstecgi.cgi setUPnPCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.006
CVE-2025-3666
TOTOLINK A3700R cstecgi.cgi setDdnsCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.006
CVE-2025-3675
TOTOLINK A3700R cstecgi.cgi setL2tpServerCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.006
1 / 2Next →