CVE-2020-27368: Totolink a702r Firmware

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.

Affected products

  • Totolink a702r Firmware: version 1.0.0-b20161227.1023 only

Published 2021-01-14. Last modified 2026-06-17.