VendorsTOTOLINKa3700r_firmware9.1.2u.5822_b20200513
Vulnerabilities

TOTOLINK A3700R Firmware 9.1.2u.6134 B20201202 9.1.2u.5822_b20200513

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2023-52027
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.
Published 2024-01-11 · Modified
9.8EPSS 0.017
CVE-2023-52028
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.017
CVE-2023-52029
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setDiagnosisCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.017
CVE-2023-52030
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.
Published 2024-01-11 · Modified
9.8EPSS 0.015
CVE-2023-52031
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function.
Published 2024-01-11 · Modified
9.8EPSS 0.015
CVE-2023-50147
There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513.
Published 2023-12-22 · Modified
9.8EPSS 0.012
CVE-2024-42543
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
Published 2024-08-12 · Modified
9.8EPSS 0.007
CVE-2024-42545
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.
Published 2024-08-12 · Modified
9.8EPSS 0.007
CVE-2026-1143
TOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg buffer overflow
Published 2026-01-19 · Analyzed
9.0EPSS 0.007
CVE-2024-7160
TOTOLINK A3700R cstecgi.cgi setWanCfg command injection
Published 2024-07-28 · Modified
8.8EPSS 0.030
CVE-2025-3663
TOTOLINK A3700R Password cstecgi.cgi setWiFiEasyGuestCfg access control
Published 2025-04-16 · Analyzed
8.2EPSS 0.113
CVE-2024-7156
TOTOLINK A3700R apmib Configuration ExportSettings.sh information disclosure
Published 2024-07-28 · Modified
7.5EPSS 0.133
CVE-2024-7154
TOTOLINK A3700R Password Reset wizard.html access control
Published 2024-07-28 · Modified
7.5EPSS 0.004
CVE-2025-3668
TOTOLINK A3700R cstecgi.cgi setScheduleCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.014
CVE-2025-3666
TOTOLINK A3700R cstecgi.cgi setDdnsCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.006
CVE-2025-3667
TOTOLINK A3700R cstecgi.cgi setUPnPCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.006
CVE-2025-3675
TOTOLINK A3700R cstecgi.cgi setL2tpServerCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.006
CVE-2025-3664
TOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.006
CVE-2025-3665
TOTOLINK A3700R cstecgi.cgi setSmartQosCfg access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.006
CVE-2025-3674
TOTOLINK A3700R cstecgi.cgi setUrlFilterRules access control
Published 2025-04-16 · Analyzed
6.9EPSS 0.006