cbcvebase.

Totolink A3002R Firmware vulnerabilities

61 known vulnerabilities affecting totolink/a3002r_firmware.

Total CVEs
61
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH33MEDIUM17LOW1

Vulnerabilities

Page 2 of 4
CVE-2025-4830P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4830 [HIGH] CWE-119 CVE-2025-4830: A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A300 A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this issue is some unknown functionality of the file /boafrm/formSysCmd of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remo
nvd
CVE-2025-4826P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4826 [HIGH] CWE-119 CVE-2025-4826: A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A300 A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely
nvd
CVE-2025-4730P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-16
CVE-2025-4730 [HIGH] CWE-119 CVE-2025-4730: A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel of the component HTTP POST Request Handler. The manipulation of the argument devicemac1 leads to buffer overflow. The attack may be launched remotely. The exploit
nvd
CVE-2025-4834P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4834 [HIGH] CWE-119 CVE-2025-4834: A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been cl A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been classified as critical. Affected is an unknown function of the file /boafrm/formSetLg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit
nvd
CVE-2025-4827P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4827 [HIGH] CWE-119 CVE-2025-4827: A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3 A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exp
nvd
CVE-2025-4835P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4835 [HIGH] CWE-119 CVE-2025-4835: A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been de A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of the argument redirect-url leads to buffer overflow. The attack can be launc
nvd
CVE-2024-34195P3CRITICALCVSS 9.8v1.1.1-b202008242024-08-28
CVE-2024-34195 [CRITICAL] CWE-787 CVE-2024-34195: TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. I TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversight leads to potential buffer overflow under specific circumstances. For instance, by invoking the formWlanRedir
nvd
CVE-2024-54907P3HIGHCVSS 8.8v4.0.0-b20230531.14042024-12-26
CVE-2024-54907 [HIGH] CWE-94 CVE-2024-54907: TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
nvd
CVE-2025-45863P3CRITICALCVSS 9.8v4.0.0-b20230531.14042025-05-13
CVE-2025-45863 [CRITICAL] CWE-120 CVE-2025-45863: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr par TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.
nvd
CVE-2025-45865P3CRITICALCVSS 9.8v4.0.0-b20230531.14042025-05-13
CVE-2025-45865 [CRITICAL] CWE-120 CVE-2025-45865: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr pa TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.
nvd
CVE-2025-45861P3CRITICALCVSS 9.8v4.0.0-b20230531.14042025-05-13
CVE-2025-45861 [CRITICAL] CWE-120 CVE-2025-45861: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.
nvd
CVE-2024-42520P3CRITICALCVSS 9.8v4.0.0-b20230531.14042024-08-12
CVE-2024-42520 [CRITICAL] CWE-120 CVE-2024-42520: TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formP TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.
nvd
CVE-2025-6393P3HIGHCVSS 7.5v4.0.0-b20230531.14042025-06-21
CVE-2025-6393 [HIGH] CWE-119 CVE-2025-6393: A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0- A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads
nvd
CVE-2025-4729P3MEDIUMCVSS 6.3v3.0.0-b20230809.16152025-05-16
CVE-2025-4729 [MEDIUM] CWE-74 CVE-2025-4729: A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to command injection. The attack can be launched remotel
nvd
CVE-2022-40111P3CRITICALCVSS 9.8v1.1.1-b20200824.01282022-09-06
CVE-2022-40111 [CRITICAL] CWE-798 CVE-2022-40111: In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardc In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.
nvd
CVE-2025-25635P3HIGHCVSS 8.0v1.1.1-b20200824.01282025-02-28
CVE-2025-25635 [HIGH] CWE-120 CVE-2025-25635: TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability ar TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.
nvd
CVE-2025-25610P3HIGHCVSS 8.0v1.1.1-b20200824.01282025-02-28
CVE-2025-25610 [HIGH] CWE-120 CVE-2025-25610: TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability ar TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.
nvd
CVE-2025-25609P3HIGHCVSS 8.0v1.1.1-b20200824.01282025-02-28
CVE-2025-25609 [HIGH] CWE-120 CVE-2025-25609: TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability ar TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa
nvd
CVE-2022-40109P3CRITICALCVSS 9.8v1.1.1-b20200824.01282022-09-06
CVE-2022-40109 [CRITICAL] CWE-276 CVE-2022-40109: TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via b TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.
nvd
CVE-2024-33820P3HIGHCVSS 7.5v4.0.0-b20230531.14042024-05-01
CVE-2024-33820 [HIGH] CWE-120 CVE-2024-33820: Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulner Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow.
nvd