TOTOLINK A3100R V4.1.2cu.5050B20200504 and V4.1.2cu.5247B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050B20200504 in adm/ntm.asp via the hosTime parameters.