cbcvebase.

Totolink A3000Ru Firmware vulnerabilities

25 known vulnerabilities affecting totolink/a3000ru_firmware.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH10MEDIUM2

Vulnerabilities

Page 2 of 2
CVE-2025-28026P3HIGHCVSS 7.3v5.9c.5185_b202011282025-04-22
CVE-2025-28026 [HIGH] CWE-121 CVE-2025-28026: TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128 TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi.
nvd
CVE-2025-28027P3HIGHCVSS 7.3v5.9c.5185_b202011282025-04-22
CVE-2025-28027 [HIGH] CWE-121 CVE-2025-28027: TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128 TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 was found to contain a buffer overflow vulnerability in downloadFile.cgi.
nvd
CVE-2022-36615P3HIGHCVSS 7.8v4.1.2cu.5185_b202011282022-08-29
CVE-2022-36615 [HIGH] CWE-798 CVE-2022-36615: TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
nvd
CVE-2025-2955P4MEDIUMCVSS 5.3≤ 5.9c.51852025-03-30
CVE-2025-2955 [MEDIUM] CWE-266 CVE-2025-2955: A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. Th A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/ExportIbmsConfig.sh of the component IBMS Configuration File Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to
nvd
CVE-2025-2688P4MEDIUMCVSS 4.3≤ 5.9c.51852025-03-24
CVE-2025-2688 [MEDIUM] CWE-266 CVE-2025-2688: A vulnerability classified as problematic was found in TOTOLINK A3000RU up to 5.9c.5185. Affected by A vulnerability classified as problematic was found in TOTOLINK A3000RU up to 5.9c.5185. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ExportSyslog.sh of the component Syslog Configuration File Handler. The manipulation leads to improper access controls. The attack needs to be done within the local network. The exploi
nvd