Totolink
Totolink A3700r Firmware: vulnerabilidades y CVE
Totolink A3700r Firmware tiene 43 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 17 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE43
Últimos 12 meses1
Críticas17
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-1143 | Alta (7.4) | 0.74% | — | 19 ene 2026 | A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument ssid can lead to buffer… |
| CVE-2025-3675 | Media (6.9) | 0.62% | — | 16 abr 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to… |
| CVE-2025-3674 | Media (6.9) | 0.59% | — | 16 abr 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation… |
| CVE-2025-3668 | Media (6.9) | 1.4% | — | 16 abr 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to… |
| CVE-2025-3667 | Media (6.9) | 0.64% | — | 16 abr 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access… |
| CVE-2025-3666 | Media (6.9) | 0.64% | — | 16 abr 2025 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper… |
| CVE-2025-3665 | Media (6.9) | 0.61% | — | 16 abr 2025 | A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads… |
| CVE-2025-3664 | Media (6.9) | 0.61% | — | 16 abr 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper… |
| CVE-2025-3663 | Media (6.9) | 11% | — | 16 abr 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the… |
| CVE-2024-42545 | Crítica (9.8) | 0.66% | — | 12 ago 2024 | TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function. |
| CVE-2024-42543 | Crítica (9.8) | 0.66% | — | 12 ago 2024 | TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function. |
| CVE-2024-7160 | Media (5.3) | 3.0% | — | 28 jul 2024 | A vulnerability classified as critical has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to… |
| CVE-2024-7156 | Media (6.9) | 13% | — | 28 jul 2024 | A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/ExportSettings.sh of the component apmib… |
| CVE-2024-7154 | Media (5.3) | 0.43% | — | 28 jul 2024 | A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file /wizard.html of the component Password Reset Handler. The… |
| CVE-2024-37640 | Alta (8.8) | 0.62% | — | 14 jun 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg. |
| CVE-2024-37639 | Alta (8.8) | 0.61% | — | 14 jun 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules. |
| CVE-2024-37637 | Crítica (9.8) | 0.67% | — | 14 jun 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg. |
| CVE-2024-37635 | Crítica (9.8) | 0.66% | — | 13 jun 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg |
| CVE-2024-37634 | Crítica (9.8) | 0.67% | — | 13 jun 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg. |
| CVE-2024-37633 | Alta (8.8) | 0.61% | — | 13 jun 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg |
| CVE-2024-37632 | Crítica (9.8) | 0.64% | — | 13 jun 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth . |
| CVE-2024-37631 | Alta (8.8) | 0.61% | — | 13 jun 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule. |
| CVE-2024-22663 | Crítica (9.8) | 1.7% | — | 23 ene 2024 | TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg |
| CVE-2024-22662 | Crítica (9.8) | 0.86% | — | 23 ene 2024 | TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules |
| CVE-2024-22660 | Crítica (9.8) | 0.86% | — | 23 ene 2024 | TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg |
| CVE-2023-52031 | Crítica (9.8) | 1.5% | — | 11 ene 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function. |
| CVE-2023-52030 | Crítica (9.8) | 1.5% | — | 11 ene 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function. |
| CVE-2023-52029 | Crítica (9.8) | 1.7% | — | 11 ene 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setDiagnosisCfg function. |
| CVE-2023-52028 | Crítica (9.8) | 1.7% | — | 11 ene 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function. |
| CVE-2023-52027 | Crítica (9.8) | 1.7% | — | 11 ene 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.