← Vulnerability feed

Vulnerability record · CVE-2021-35327 · published 5 August 2021

CVE-2021-35327: Totolink a720r firmware missing authorization vulnerability

TTotolink · A720r Firmware

A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.

9.8 CVSS 3.1 Critical EPSS 1.4% · top 28.9% CWE-862 · Missing authorization
9.8CVSS 3.1 base score, v2 7.5
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35327 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23064Totolink a720r firmware incorrect authorization vulnerabilityTOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.EPSS 0.70%9.8CVE-2021-45740Totolink a720r firmware vulnerabilityTOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers…EPSS 1.4%9.8CVE-2021-45742Totolink a720r firmware command injection vulnerabilityTOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows a…EPSS 3.1%9.8CVE-2021-44247Totolink a720r firmware command injection vulnerabilityTotolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command inje…EPSS 2.8%9.8CVE-2021-35324Totolink a720r firmware vulnerabilityA vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass authentication.EPSS 10%9.8CVE-2021-27710Totolink x5000r firmware os command injection vulnerabilityCommand Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo…EPSS 7.9%9.8CVE-2021-27708Totolink x5000r firmware os command injection vulnerabilityCommand Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allo…EPSS 7.6%7.8CVE-2022-36610Totolink a720r firmware hard-coded credentials vulnerabilityTOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2021-35327), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.