📦 A7100ru Firmware

by Totolink

🔍 What is A7100ru Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-44655

CRITICAL CVSS 9.8 Jul 21, 2025

This vulnerability in TOTOLink routers allows attackers to bypass FTP directory restrictions due to misconfigured vsftpd settings. Attackers can access system files, escalate privileges, or use the co...

CVE-2023-7095

CRITICAL CVSS 9.8 Dec 25, 2023

A critical buffer overflow vulnerability in Totolink A7100RU routers allows remote attackers to execute arbitrary code via specially crafted HTTP POST requests to the login endpoint. This affects devi...

CVE-2023-6906

CRITICAL CVSS 9.8 Dec 18, 2023

This critical vulnerability allows remote attackers to execute arbitrary code on Totolink A7100RU routers by sending a specially crafted HTTP POST request that triggers a buffer overflow. Attackers ca...

CVE-2023-33556

CRITICAL CVSS 9.8 Jun 7, 2023

This CVE describes a command injection vulnerability in TOTOLink A7100RU routers that allows attackers to execute arbitrary commands on the device. The vulnerability exists in the staticGw parameter o...

CVE-2023-30053

CRITICAL CVSS 9.8 May 5, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A7100RU routers. Attackers can inject malicious commands through specific parameters, potentially gaining full cont...

CVE-2023-26848

CRITICAL CVSS 9.8 Apr 7, 2023

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers via the org parameter in the setting/delStaticDhcpRules endpoint, allowing attackers to execute arbitrary commands on t...

CVE-2023-27232

CRITICAL CVSS 9.8 Mar 28, 2023

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit this by sending specially craf...

CVE-2023-27229

CRITICAL CVSS 9.8 Mar 28, 2023

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit this by sending specially craf...

CVE-2023-25395

CRITICAL CVSS 9.8 Mar 8, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOlink A7100RU routers via command injection in the 'ou' parameter. Attackers can gain full control of affected routers, p...

CVE-2023-24236

CRITICAL CVSS 9.8 Feb 16, 2023

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink A7100RU routers by injecting malicious commands into the province parameter. Attackers can gain full control of aff...

CVE-2022-28581

CRITICAL CVSS 9.8 May 5, 2022

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit the setWiFiAdvancedCfg interfa...

CVE-2022-28583

CRITICAL CVSS 9.8 May 5, 2022

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit the setWiFiWpsCfg interface by...