VendorsTOTOLINKa7100ruany version
Vulnerabilities

TOTOLINK A7100RU any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2023-7095
Totolink A7100RU HTTP POST Request main buffer overflow
Published 2023-12-25 · Modified
10.0EPSS 0.137
CVE-2022-28577
It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Published 2022-05-05 · Modified
10.0EPSS 0.030
CVE-2022-28578
It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Published 2022-05-05 · Modified
10.0EPSS 0.030
CVE-2022-28579
It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Published 2022-05-05 · Modified
10.0EPSS 0.030
CVE-2022-28580
It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Published 2022-05-05 · Modified
10.0EPSS 0.030
CVE-2022-28581
It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Published 2022-05-05 · Modified
10.0EPSS 0.030
CVE-2022-28582
It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Published 2022-05-05 · Modified
10.0EPSS 0.030
CVE-2022-28583
It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Published 2022-05-05 · Modified
10.0EPSS 0.030
CVE-2022-28584
It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Published 2022-05-05 · Modified
10.0EPSS 0.030
CVE-2022-28575
It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payload
Published 2022-05-05 · Modified
10.0EPSS 0.030
CVE-2023-6906
Totolink A7100RU HTTP POST Request main buffer overflow
Published 2023-12-18 · Modified
10.0EPSS 0.019
CVE-2023-30053
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
Published 2023-05-05 · Modified
9.8EPSS 0.021
CVE-2023-30054
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.
Published 2023-05-05 · Modified
9.8EPSS 0.021
CVE-2022-46631
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.
Published 2022-12-15 · Modified
9.8EPSS 0.021
CVE-2022-46634
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.
Published 2022-12-15 · Modified
9.8EPSS 0.021
CVE-2023-27135
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg.
Published 2023-03-23 · Modified
9.8EPSS 0.020
CVE-2023-27231
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.
Published 2023-03-28 · Modified
9.8EPSS 0.020
CVE-2023-27229
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg.
Published 2023-03-28 · Modified
9.8EPSS 0.020
CVE-2022-44844
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.
Published 2022-11-25 · Modified
9.8EPSS 0.020
CVE-2022-44843
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.
Published 2022-11-25 · Modified
9.8EPSS 0.020
CVE-2023-33556
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.
Published 2023-06-07 · Modified
9.8EPSS 0.020
CVE-2022-48125
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password parameter in the setting/setOpenVpnCertGenerationCfg function.
Published 2023-01-20 · Modified
9.8EPSS 0.020
CVE-2022-48126
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the setting/setOpenVpnCertGenerationCfg function.
Published 2023-01-20 · Modified
9.8EPSS 0.020
CVE-2022-48124
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the setting/setOpenVpnCertGenerationCfg function.
Published 2023-01-20 · Modified
9.8EPSS 0.020
CVE-2022-48123
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setting/delStaticDhcpRules function.
Published 2023-01-20 · Modified
9.8EPSS 0.020
CVE-2022-48122
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the setting/delStaticDhcpRules function.
Published 2023-01-20 · Modified
9.8EPSS 0.020
CVE-2022-48121
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the setting/delStaticDhcpRules function.
Published 2023-01-20 · Modified
9.8EPSS 0.020
CVE-2023-24238
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.
Published 2023-02-16 · Modified
9.8EPSS 0.019
CVE-2023-24276
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.
Published 2023-02-06 · Modified
9.8EPSS 0.019
CVE-2023-25395
TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou parameter at /setting/delStaticDhcpRules.
Published 2023-03-08 · Modified
9.8EPSS 0.019
CVE-2023-26848
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.
Published 2023-04-07 · Modified
9.8EPSS 0.019
CVE-2023-26978
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.
Published 2023-04-07 · Modified
9.8EPSS 0.019
CVE-2023-24236
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.
Published 2023-02-16 · Modified
9.8EPSS 0.019
CVE-2023-27232
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg.
Published 2023-03-28 · Modified
9.8EPSS 0.019
CVE-2022-47853
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root shell through a specially constructed payload.
Published 2023-01-17 · Modified
9.8EPSS 0.019
CVE-2023-24184
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability.
Published 2023-02-21 · Modified
9.8EPSS 0.013
CVE-2025-44655
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.
Published 2025-07-21 · Modified
9.8EPSS 0.003