totolink Vulnerabilities and Affected Products
Vulnerabilities associated with a720r_firmware.
Products
Clear product- A8000RU50 vulnerabilities
- A7100RU42 vulnerabilities
- A3002RU33 vulnerabilities
- x2000r_firmware29 vulnerabilities
- A702R27 vulnerabilities
- x6000r_firmware27 vulnerabilities
- A3002R26 vulnerabilities
- x5000r_firmware26 vulnerabilities
- X1525 vulnerabilities
- A3300R20 vulnerabilities
- A3600R20 vulnerabilities
- EX1200T19 vulnerabilities
- a3600r_firmware17 vulnerabilities
- T616 vulnerabilities
- A3700R15 vulnerabilities
- ex200_firmware15 vulnerabilities
- N300RH15 vulnerabilities
- a3700r_firmware14 vulnerabilities
- AC1200 T814 vulnerabilities
- LR1200GB14 vulnerabilities
- LR35014 vulnerabilities
- N150RT14 vulnerabilities
- N200RE14 vulnerabilities
- cp45013 vulnerabilities
- ac1200_t8_firmware12 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-4270MEDIUM | TOTOLINK A720R Config cstecgi.cgi information disclosureA vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl with the input getInitCfg/getSysStatusCfg leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS6.9v4.0 | EPSS13.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-35327CRITICAL | totolink a720r_firmware Missing AuthorizationA vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request. CWE-862Aug 5, 2021 | CVSS9.8v3.1 | EPSS1.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |