VendorsTOTOLINKa720r_firmwareall versions
Vulnerabilities

TOTOLINK A720r Firmware 4.1.5cu.470 B20200911

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2021-27710
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "ip" parameter is directly passed to the attacker, allowing them to control the "ip" field to attack the OS.
Published 2021-04-14 · Modified
10.0EPSS 0.079
CVE-2021-27708
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "command" parameter is directly passed to the attacker, allowing them to control the "command" field to attack the OS.
Published 2021-04-14 · Modified
10.0EPSS 0.076
CVE-2021-45742
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
Published 2022-02-04 · Modified
10.0EPSS 0.031
CVE-2021-35324
A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication.
Published 2021-08-05 · Modified
9.8EPSS 0.104
CVE-2021-44247
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.
Published 2022-02-04 · Modified
9.8EPSS 0.028
CVE-2021-35327
A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.
Published 2021-08-05 · Modified
9.8EPSS 0.014
CVE-2021-45740
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the pin parameter.
Published 2022-02-04 · Modified
9.8EPSS 0.014
CVE-2025-9303
TOTOLINK A720R cstecgi.cgi setParentalRules buffer overflow
Published 2025-08-21 · Analyzed
9.8EPSS 0.009
CVE-2023-23064
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
Published 2023-02-17 · Modified
9.8EPSS 0.007
CVE-2024-8869
TOTOLINK A720R exportOvpn os command injection
Published 2024-09-15 · Analyzed
8.1EPSS 0.017
CVE-2021-44246
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain a stack overflow in the function setNoticeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IpTo parameter.
Published 2022-02-04 · Modified
7.8EPSS 0.012
CVE-2021-45739
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.
Published 2022-02-04 · Modified
7.8EPSS 0.012
CVE-2021-45737
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the Host parameter.
Published 2022-02-04 · Modified
7.8EPSS 0.012
CVE-2022-36456
TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
Published 2022-08-25 · Modified
7.8EPSS 0.010
CVE-2022-36610
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
Published 2022-08-28 · Modified
7.8EPSS 0.003
CVE-2021-35325
A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).
Published 2021-08-05 · Modified
7.5EPSS 0.133
CVE-2025-4270
TOTOLINK A720R Config cstecgi.cgi information disclosure
Published 2025-05-05 · Analyzed
7.5EPSS 0.131
CVE-2021-35326
A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via sending a crafted HTTP request.
Published 2021-08-05 · Modified
7.5EPSS 0.025
CVE-2022-38535
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function.
Published 2022-09-15 · Modified
7.2EPSS 0.021
CVE-2022-38534
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function.
Published 2022-09-15 · Modified
7.2EPSS 0.021
CVE-2025-4268
TOTOLINK A720R cstecgi.cgi missing authentication
Published 2025-05-05 · Analyzed
6.9EPSS 0.011
CVE-2025-4271
TOTOLINK A720R cstecgi.cgi information disclosure
Published 2025-05-05 · Analyzed
6.9EPSS 0.006
CVE-2025-4269
TOTOLINK A720R Log cstecgi.cgi access control
Published 2025-05-05 · Analyzed
6.9EPSS 0.006
CVE-2025-60682
A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed via system() without any sanitization or escaping. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device.
Published 2025-11-13 · Modified
6.5EPSS 0.015
CVE-2025-60683
A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handles network interface reinitialization from '/var/system/linux_vlan_reinit'. Input is only partially validated by checking the prefix of interface names, and is concatenated into shell commands executed via system() without escaping. An attacker with write access to this file can execute arbitrary commands on the device.
Published 2025-11-13 · Modified
6.5EPSS 0.010
CVE-2021-43662
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.
Published 2022-03-30 · Modified
6.5EPSS 0.005
CVE-2025-60685
A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file using fgets() into a local buffer and subsequently parses the line using sscanf() into a single-byte variable with the %s format specifier. Maliciously crafted /proc/stat content can overwrite adjacent stack memory, potentially allowing an attacker with filesystem write privileges to execute arbitrary code on the device.
Published 2025-11-13 · Modified
5.1EPSS 0.002
CVE-2025-60686
A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using sscanf() with "%s" format specifiers into fixed-size stack buffers without length validation. Specifically, one function writes user-controlled data into a single-byte buffer, and the other into adjacent small arrays without bounds checking. An attacker who controls the contents of /proc/net/arp can trigger memory corruption, leading to denial of service or potential arbitrary code execution.
Published 2025-11-13 · Modified
5.1EPSS 0.002