TOTOLINK A800R, A810R, A830R, A950RG, A3000RU, and A3100R Pre-Authentication Remote Command Execution Vulnerability

Vulnerability

A pre-authentication remote command execution vulnerability has been identified in several TOTOLINK router models, including the A800R, A810R, A830R, A950RG, A3000RU, and A3100R. The vulnerability arises in the NTPSyncWithHost function, where the hostTime parameter is improperly handled, allowing for unauthorized command execution on the device.

Impact

Exploitation of this vulnerability allows for remote command execution on the affected devices.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
9.1
remediation
7.7
relevance
0.0
threat
6.5
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.