📦 A720r Firmware

by Totolink

🔍 What is A720r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-23064

CRITICAL CVSS 9.8 Feb 17, 2023

CVE-2023-23064 is an incorrect access control vulnerability in TOTOLINK A720R routers that allows unauthenticated attackers to bypass authentication and gain administrative access. This affects users ...

CVE-2021-45740

CRITICAL CVSS 9.8 Feb 4, 2022

This vulnerability is a stack overflow in the setWiFiWpsStart function of TOTOLINK A720R routers. Attackers can send specially crafted pin parameter values to cause a Denial of Service (DoS), potentia...

CVE-2021-45742

CRITICAL CVSS 9.8 Feb 4, 2022

This CVE describes a command injection vulnerability in TOTOLINK A720R routers that allows attackers to execute arbitrary commands via the QUERY_STRING parameter. Attackers can gain full control of af...

CVE-2021-44247

CRITICAL CVSS 9.8 Feb 4, 2022

This CVE describes a command injection vulnerability in Totolink router firmware that allows attackers to execute arbitrary commands via the IpFrom parameter in the setNoticeCfg function. Attackers ca...

CVE-2021-35324

CRITICAL CVSS 9.8 Aug 5, 2021

This vulnerability allows attackers to bypass authentication on TOTOLINK A720R routers by exploiting a flaw in the Form_Login function. Attackers can gain unauthorized access to the router's administr...

CVE-2021-35327

CRITICAL CVSS 9.8 Aug 5, 2021

This vulnerability allows attackers to enable Telnet service on TOTOLINK A720R routers via a crafted POST request, then gain access using default credentials. Attackers can achieve remote code executi...

CVE-2021-27710

CRITICAL CVSS 9.8 Apr 14, 2021

This CVE describes a critical command injection vulnerability in TOTOLINK routers that allows remote attackers to execute arbitrary operating system commands by sending specially crafted HTTP requests...

CVE-2021-27708

CRITICAL CVSS 9.8 Apr 14, 2021

This CVE describes a critical command injection vulnerability in TOTOLINK X5000R and A720R routers that allows remote attackers to execute arbitrary operating system commands by sending specially craf...

CVE-2021-45737

HIGH CVSS 7.5 Feb 4, 2022

This vulnerability is a stack overflow in the Form_Login function of TOTOLINK A720R routers, allowing attackers to cause Denial of Service (DoS) by sending specially crafted Host parameters. It affect...

CVE-2021-44246

HIGH CVSS 7.5 Feb 4, 2022

This vulnerability is a stack overflow in the setNoticeCfg function of Totolink routers, allowing attackers to cause Denial of Service (DoS) by sending specially crafted requests with the IpTo paramet...

CVE-2021-35326

HIGH CVSS 7.5 Aug 5, 2021

This vulnerability allows attackers to download the router's configuration file by sending a specially crafted HTTP request to the TOTOLINK A720R router. This affects users running firmware version v4...

CVE-2025-60682

MEDIUM CVSS 6.5 Nov 13, 2025

This CVE describes a command injection vulnerability in ToToLink A720R router firmware that allows unauthenticated remote attackers to execute arbitrary commands on affected devices. The vulnerability...

CVE-2025-60683

MEDIUM CVSS 6.5 Nov 13, 2025

This CVE describes a command injection vulnerability in ToToLink A720R router firmware that allows arbitrary command execution. Attackers with write access to the /var/system/linux_vlan_reinit file ca...

CVE-2025-60685

MEDIUM CVSS 5.1 Nov 13, 2025

A stack buffer overflow vulnerability in ToToLink A720R router firmware allows attackers with filesystem write access to execute arbitrary code by crafting malicious /proc/stat content. This affects u...

CVE-2025-60686

MEDIUM CVSS 5.1 Nov 13, 2025

This vulnerability allows local attackers to trigger stack-based buffer overflows in ToToLink router firmware by manipulating ARP table data. Attackers can cause denial of service or potentially execu...

CVE-2025-4270

MEDIUM CVSS 5.3 May 5, 2025

This vulnerability in TOTOLINK A720R routers allows remote attackers to access sensitive system configuration information without authentication. By manipulating the topicurl parameter in the Config H...

CVE-2025-4268

MEDIUM CVSS 5.3 May 5, 2025

This vulnerability allows unauthenticated remote attackers to reboot TOTOLINK A720R routers by accessing the /cgi-bin/cstecgi.cgi endpoint with a specific parameter. It affects TOTOLINK A720R routers ...

CVE-2024-8869

MEDIUM CVSS 5.0 Sep 15, 2024

This critical vulnerability in TOTOLINK A720R routers allows remote attackers to execute arbitrary operating system commands through the exportOvpn function. It affects users of TOTOLINK A720R firmwar...