📦 A3100r Firmware

by Totolink

🔍 What is A3100r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-45789

CRITICAL CVSS 9.8 May 8, 2025

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3100R routers via a buffer overflow in the setParentalRules function. Attackers can exploit this by sending specially ...

CVE-2025-45787

CRITICAL CVSS 9.8 May 8, 2025

CVE-2025-45787 is a critical buffer overflow vulnerability in TOTOLINK A3100R routers that allows remote attackers to execute arbitrary code by sending specially crafted data to the comment parameter ...

CVE-2025-28034

CRITICAL CVSS 9.8 Apr 22, 2025

This CVE describes a pre-authentication remote command execution vulnerability in multiple TOTOLINK router models. Attackers can execute arbitrary commands on affected devices without authentication b...

CVE-2025-28256

CRITICAL CVSS 9.8 Mar 28, 2025

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3100R routers by exploiting improper input sanitization in the setWebWlanIdx function. Attackers can gain full control...

CVE-2024-42546

CRITICAL CVSS 9.8 Aug 12, 2024

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3100R routers by exploiting a buffer overflow in the password parameter during authentication. Attackers can gain full...

CVE-2022-29644

CRITICAL CVSS 9.8 May 18, 2022

This vulnerability involves a hard-coded password for the telnet service in TOTOLINK A3100R routers, allowing attackers to gain unauthorized administrative access. It affects users of specific firmwar...

CVE-2021-46009

CRITICAL CVSS 9.8 Mar 30, 2022

This vulnerability allows unauthenticated attackers to access sensitive pages and modify admin configurations on Totolink A3100R routers. It affects all users running the vulnerable firmware version w...

CVE-2022-26206

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a critical command injection vulnerability in multiple Totolink router models. Attackers can execute arbitrary system commands by sending specially crafted requests to the setLangua...

CVE-2022-26208

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the webWlanIdx parameter in the setWebWlanIdx function. ...

CVE-2022-26210

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the FileName parameter in the setUpgradeFW function. Att...

CVE-2022-26212

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the setDeviceName function. Attackers can exploit this b...

CVE-2022-26214

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the host_time parameter in the NTPSyncWithHost function....

CVE-2021-44247

CRITICAL CVSS 9.8 Feb 4, 2022

This CVE describes a command injection vulnerability in Totolink router firmware that allows attackers to execute arbitrary commands via the IpFrom parameter in the setNoticeCfg function. Attackers ca...

CVE-2025-4496

HIGH CVSS 8.8 May 10, 2025

A critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by manipulating the FileName parameter in the CloudACMunualUpdate function. This affects ...

CVE-2025-28028

HIGH CVSS 7.3 Apr 23, 2025

A buffer overflow vulnerability in TOTOLINK routers' downloadFile.cgi component allows attackers to execute arbitrary code by sending specially crafted requests to the v5 parameter. This affects multi...

CVE-2025-28032

HIGH CVSS 7.3 Apr 22, 2025

This CVE describes a pre-authentication buffer overflow vulnerability in multiple TOTOLINK router models. Attackers can exploit this by sending specially crafted requests to the setNoticeCfg function ...

CVE-2024-7157

HIGH CVSS 8.8 Jul 28, 2024

A critical buffer overflow vulnerability in TOTOLINK A3100R routers allows remote attackers to execute arbitrary code by manipulating the http_host parameter in the getSaveConfig function. This affect...

CVE-2024-36650

HIGH CVSS 7.5 Jun 11, 2024

This buffer overflow vulnerability in TOTOLINK AC1200 router firmware allows attackers to send specially crafted HTTP or MQTT requests to the 'setNoticeCfg' function, potentially causing denial-of-ser...

CVE-2022-28935

HIGH CVSS 7.2 Jul 6, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands on affected devices. The vulnerability affects specific firm...

CVE-2022-29638

HIGH CVSS 7.5 May 18, 2022

This CVE describes a stack overflow vulnerability in TOTOLINK A3100R routers that allows attackers to cause a Denial of Service (DoS) by sending a specially crafted POST request to the comment paramet...

CVE-2022-29640

HIGH CVSS 7.5 May 18, 2022

This vulnerability is a stack overflow in TOTOLINK A3100R routers that allows attackers to cause Denial of Service (DoS) by sending specially crafted POST requests to the setPortForwardRules function....

CVE-2022-29642

HIGH CVSS 7.5 May 18, 2022

This vulnerability is a stack overflow in TOTOLINK A3100R routers that allows attackers to cause Denial of Service (DoS) by sending specially crafted POST requests to the setUrlFilterRules function. I...

CVE-2021-44246

HIGH CVSS 7.5 Feb 4, 2022

This vulnerability is a stack overflow in the setNoticeCfg function of Totolink routers, allowing attackers to cause Denial of Service (DoS) by sending specially crafted requests with the IpTo paramet...