📦 A7000r Firmware

by Totolink

🔍 What is A7000r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-51452

CRITICAL CVSS 9.8 Aug 13, 2025

This vulnerability allows unauthenticated attackers to bypass login authentication on TOTOLINK A7000R routers by sending a specific request to formLoginAuth.htm. This affects all users running the vul...

CVE-2024-28639

CRITICAL CVSS 9.8 Mar 16, 2024

A buffer overflow vulnerability in TOTOLink routers allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted data to the IP field. This affects TOTOLin...

CVE-2023-49417

CRITICAL CVSS 9.8 Dec 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on TOTOLink A7000R routers via a stack overflow in the setOpModeCfg function. Attackers can exploit this to gain full control of af...

CVE-2023-45984

CRITICAL CVSS 9.8 Oct 16, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected TOTOLINK routers via a stack overflow in the setLanguageCfg function. Attackers can exploit this by sending specially c...

CVE-2022-27003

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a critical command injection vulnerability in Totolink routers that allows attackers to execute arbitrary system commands via the Tunnel 6rd function. Attackers can exploit this by ...

CVE-2022-27005

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a critical command injection vulnerability in Totolink routers that allows attackers to execute arbitrary commands via the hostName parameter in the setWanCfg function. Attackers ca...

CVE-2025-63459

HIGH CVSS 7.5 Oct 31, 2025

This vulnerability is a stack overflow in Totolink A7000R routers that allows attackers to cause a Denial of Service (DoS) by sending a specially crafted request to the ssid5g parameter. It affects us...

CVE-2025-63460

HIGH CVSS 7.5 Oct 31, 2025

This vulnerability is a stack overflow in Totolink A7000R routers that allows attackers to cause a Denial of Service (DoS) by sending a specially crafted request to the ssid5g parameter. It affects us...

CVE-2025-63462

HIGH CVSS 7.5 Oct 31, 2025

This CVE describes a stack overflow vulnerability in Totolink A7000R routers via the wifiOff parameter. Attackers can send crafted requests to trigger a Denial of Service (DoS), crashing the device. O...

CVE-2024-7212

HIGH CVSS 8.8 Jul 30, 2024

This critical vulnerability in TOTOLINK A7000R routers allows remote attackers to execute arbitrary code via a buffer overflow in the loginauth function when manipulating the password parameter. Attac...

CVE-2026-1548

MEDIUM CVSS 6.3 Jan 28, 2026

This vulnerability allows remote attackers to execute arbitrary commands on Totolink A7000R routers by injecting malicious commands into the 'url' parameter of the CloudACMunualUpdateUserdata function...

CVE-2026-1547

MEDIUM CVSS 6.3 Jan 28, 2026

This CVE describes a remote command injection vulnerability in Totolink A7000R routers. Attackers can execute arbitrary commands on affected devices by manipulating the 'plugin_name' parameter in the ...