In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
An attacker sends a specially crafted HTTP request to the formLoginAuth.htm endpoint, which results in bypassing the user identity verification procedure (CWE-288: Authentication Bypass Using an Alternate Path or Channel). The attack requires no privileges or user interaction and can be performed remotely over the network. The authentication mechanism in firmware version 9.1.0u.6115_B20201022 does not properly validate requests directed to this resource.
An attacker gains unauthorized access to the router's administrative interface, enabling full control over the device — including changing network configuration, intercepting network traffic, and potentially using the router as an entry point to the internal network. CVSS indicators point to a high impact on system confidentiality, integrity, and availability.
Apply patches available from the manufacturer according to the references. It is recommended to check the availability of updated firmware on the TOTOLINK manufacturer's website. Until the update is applied, restrict access to the router's administrative interface only to trusted hosts and disable exposure of the administrative panel on the WAN interface.
TOTOLINK A7000R with firmware version 9.1.0u.6115_B20201022
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTotolink A7000r
HWTotolinkall versionsTotolink A7000r Firmware
OSTotolink9.1.0u.6115_b20201022
Related vulnerabilities
Buffer Overflow w TOTOLINK X5000R i A7000R — RCE przez pole IP
Stack overflow w TOTOLink A7000R via setIpPortFilterRules — RCE bez uwierzytelnienia
Stack overflow w TOTOLink A7000R — funkcja setOpModeCfg
Stack overflow w TOTOLINK X5000R i A7000R — parametr lang w setLanguageCfg
Stack overflow w TOTOLINK X5000R i A7000R — funkcja UploadCustomModule