296,854
Total vulnerabilities in the database
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.
| Software | From | Fixed in |
|---|---|---|
| totolink / a3100r_firmware | 5.9c.4577 | 5.9c.4577.x |