Total
23 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-31729 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-03-07 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi. | |||||
CVE-2024-24333 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-02-01 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function. | |||||
CVE-2024-24325 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-02-01 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function. | |||||
CVE-2024-24326 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-02-01 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function. | |||||
CVE-2024-24327 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-02-01 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function. | |||||
CVE-2024-24328 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-02-01 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function. | |||||
CVE-2024-24329 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-02-01 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function. | |||||
CVE-2024-24332 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-02-01 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function. | |||||
CVE-2024-24331 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-02-01 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function. | |||||
CVE-2024-24330 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-02-01 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function. | |||||
CVE-2024-23061 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-01-18 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function. | |||||
CVE-2024-23060 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-01-18 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg function. | |||||
CVE-2024-23059 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-01-18 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnsCfg function. | |||||
CVE-2024-23058 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-01-18 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function. | |||||
CVE-2024-23057 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-01-18 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg function. | |||||
CVE-2024-22942 | 1 Totolink | 2 A3300r, A3300r Firmware | 2024-01-18 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanCfg function. | |||||
CVE-2023-46993 | 1 Totolink | 2 A3300r, A3300r Firmware | 2023-11-08 | N/A | 9.8 CRITICAL |
In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection. | |||||
CVE-2023-46992 | 1 Totolink | 2 A3300r, A3300r Firmware | 2023-11-08 | N/A | 7.5 HIGH |
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages. | |||||
CVE-2023-46976 | 1 Totolink | 2 A3300r, A3300r Firmware | 2023-11-08 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function. | |||||
CVE-2023-37173 | 1 Totolink | 2 A3300r, A3300r Firmware | 2023-07-13 | N/A | 9.8 CRITICAL |
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function. |