📦 A3600r Firmware

by Totolink

🔍 What is A3600r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-25078

CRITICAL CVSS 9.8 Feb 24, 2022

This CVE describes a command injection vulnerability in TOTOLink A3600R routers that allows attackers to execute arbitrary commands via the QUERY_STRING parameter. Attackers can gain full control of a...

CVE-2024-7187

HIGH CVSS 8.8 Jul 29, 2024

This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code via a buffer overflow in the UploadCustomModule function. Attackers can exploit this without au...

CVE-2024-7185

HIGH CVSS 8.8 Jul 29, 2024

This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code via a buffer overflow in the setWebWlanIdx function. Attackers can exploit this without authent...

CVE-2024-7184

HIGH CVSS 8.8 Jul 29, 2024

This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code via buffer overflow in the setUrlFilterRules function. Attackers can exploit this by sending sp...

CVE-2024-7182

HIGH CVSS 8.8 Jul 29, 2024

A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by manipulating the FileName parameter in the firmware upgrade function. This affe...

CVE-2024-7180

HIGH CVSS 8.8 Jul 29, 2024

A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by manipulating the 'comment' parameter in the setPortForwardRules function. This ...

CVE-2024-7178

HIGH CVSS 8.8 Jul 29, 2024

A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the setMacQos function. This affects TOTO...

CVE-2024-7176

HIGH CVSS 8.8 Jul 29, 2024

This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code via a buffer overflow in the setIpQosRules function. Attackers can exploit this by sending spec...

CVE-2024-7174

HIGH CVSS 8.8 Jul 29, 2024

A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the setdeviceName function. This affects ...

CVE-2024-7172

HIGH CVSS 8.8 Jul 28, 2024

A critical buffer overflow vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary code by manipulating the http_host parameter in the getSaveConfig function. This affect...

CVE-2022-29377

HIGH CVSS 7.5 May 24, 2022

This vulnerability is a stack buffer overflow in the Totolink A3600R router's infostat.cgi component, triggered via the CONTENT_LENGTH parameter. Attackers can exploit this to cause a Denial of Servic...

CVE-2024-7171

MEDIUM CVSS 6.3 Jul 28, 2024

This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary operating system commands via command injection in the NTPSyncWithHost function. Attackers can explo...

CVE-2024-7159

MEDIUM CVSS 5.5 Jul 28, 2024

This CVE describes a critical vulnerability in TOTOLINK A3600R routers where the Telnet service uses a hard-coded password in the product.ini file. Attackers can exploit this to gain unauthorized acce...