← Vulnerability feed

Vulnerability record · CVE-2021-35325 · published 5 August 2021

CVE-2021-35325: Totolink a720r firmware out-of-bounds write vulnerability

TTotolink · A720r Firmware

A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).

7.5 CVSS 3.1 High EPSS 13% · top 3.7% CWE-787 · Out-of-bounds write
7.5CVSS 3.1 base score, v2 5.0
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35325 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23064Totolink a720r firmware incorrect authorization vulnerabilityTOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.EPSS 0.70%9.8CVE-2021-45740Totolink a720r firmware vulnerabilityTOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers…EPSS 1.4%9.8CVE-2021-45742Totolink a720r firmware command injection vulnerabilityTOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows a…EPSS 3.1%9.8CVE-2021-44247Totolink a720r firmware command injection vulnerabilityTotolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command inje…EPSS 2.8%9.8CVE-2021-35324Totolink a720r firmware vulnerabilityA vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication.EPSS 10%9.8CVE-2021-35327Totolink a720r firmware missing authorization vulnerabilityA vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default cre…EPSS 1.4%9.8CVE-2021-27710Totolink x5000r firmware os command injection vulnerabilityCommand Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo…EPSS 7.9%9.8CVE-2021-27708Totolink x5000r firmware os command injection vulnerabilityCommand Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo…EPSS 7.6%

Source: NIST National Vulnerability Database (record CVE-2021-35325), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.