📦 A3700r Firmware

by Totolink

🔍 What is A3700r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-42543

CRITICAL CVSS 9.8 Aug 12, 2024

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3700R routers by exploiting a buffer overflow in the loginauth function's http_host parameter. Attackers can gain full...

CVE-2024-37637

CRITICAL CVSS 9.8 Jun 14, 2024

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3700R routers via a stack overflow in the setWizardCfg function. Attackers can exploit this by sending specially craft...

CVE-2024-22662

CRITICAL CVSS 9.8 Jan 23, 2024

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3700R routers by exploiting a stack overflow in the setParentalRules function. Attackers can gain full control of affe...

CVE-2023-52027

CRITICAL CVSS 9.8 Jan 11, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink A3700R routers via the NTPSyncWithHost function. Attackers can gain full control of affected devices without authen...

CVE-2023-52029

CRITICAL CVSS 9.8 Jan 11, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOlink A3700R routers via the setDiagnosisCfg function. Attackers can gain full control of affected devices without authen...

CVE-2023-52031

CRITICAL CVSS 9.8 Jan 11, 2024

This vulnerability allows remote attackers to execute arbitrary commands on TOTOlink A3700R routers via the UploadFirmwareFile function. Attackers can gain full control of affected devices without aut...

CVE-2023-46574

CRITICAL CVSS 9.8 Oct 25, 2023

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3700R routers by exploiting the FileName parameter in the UploadFirmwareFile function. Attackers can gain full control...

CVE-2024-37640

HIGH CVSS 8.8 Jun 14, 2024

This vulnerability is a stack overflow in the TOTOLINK A3700R router's setWiFiEasyGuestCfg function, allowing remote attackers to execute arbitrary code by sending specially crafted requests to the ss...

CVE-2025-3675

MEDIUM CVSS 5.3 Apr 16, 2025

This critical vulnerability in TOTOLINK A3700R routers allows attackers to bypass access controls on the setL2tpServerCfg function via the /cgi-bin/cstecgi.cgi endpoint. Attackers can remotely exploit...

CVE-2025-3668

MEDIUM CVSS 5.3 Apr 16, 2025

This vulnerability allows remote attackers to bypass access controls on TOTOLINK A3700R routers via the setScheduleCfg function in the web interface. Attackers can manipulate schedule configurations w...

CVE-2025-3664

MEDIUM CVSS 5.3 Apr 16, 2025

This critical vulnerability in TOTOLINK A3700R routers allows attackers to bypass access controls on the setWiFiEasyGuestCfg function via the /cgi-bin/cstecgi.cgi endpoint. Attackers can exploit this ...

CVE-2024-7156

MEDIUM CVSS 5.3 Jul 28, 2024

This vulnerability in TOTOLINK A3700R routers allows remote attackers to access sensitive configuration information through the ExportSettings.sh CGI script. It affects users of TOTOLINK A3700R firmwa...