cbcvebase.

Totolink A3002R Firmware vulnerabilities

61 known vulnerabilities affecting totolink/a3002r_firmware.

Total CVEs
61
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH33MEDIUM17LOW1

Vulnerabilities

Page 3 of 4
CVE-2025-55589P3MEDIUMCVSS 6.5v4.0.0-b20230531.14042025-08-18
CVE-2025-55589 [MEDIUM] CWE-78 CVE-2025-55589: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulner TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.
nvd
CVE-2021-34228P3MEDIUMCVSS 6.1v1.1.1-b202008242021-08-20
CVE-2021-34228 [MEDIUM] CWE-79 CVE-2021-34228: Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Up Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.
nvd
CVE-2025-55588P3HIGHCVSS 7.5v4.0.0-b20230531.14042025-08-18
CVE-2025-55588 [HIGH] CWE-400 CVE-2025-55588: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip param TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
nvd
CVE-2025-55587P3HIGHCVSS 7.5v4.0.0-b20230531.14042025-08-18
CVE-2025-55587 [HIGH] CWE-400 CVE-2025-55587: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname pa TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
nvd
CVE-2025-55590P3MEDIUMCVSS 6.5v4.0.0-b20230531.14042025-08-18
CVE-2025-55590 [MEDIUM] CWE-77 CVE-2025-55590: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability v TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.
nvd
CVE-2022-40112P3HIGHCVSS 7.5v1.1.1-b20200824.01282022-09-06
CVE-2022-40112 [HIGH] CWE-120 CVE-2022-40112: TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostn TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in binary /bin/boa.
nvd
CVE-2025-55586P3HIGHCVSS 7.5v4.0.0-b20230531.14042025-08-18
CVE-2025-55586 [HIGH] CWE-400 CVE-2025-55586: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url paramet TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
nvd
CVE-2025-55585P3MEDIUMCVSS 6.5v4.0.0-b20230531.14042025-08-18
CVE-2025-55585 [MEDIUM] CWE-95 CVE-2025-55585: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.
nvd
CVE-2022-40110P3HIGHCVSS 7.5v1.1.1-b20200824.01282022-09-06
CVE-2022-40110 [HIGH] CWE-120 CVE-2022-40110: TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/b TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa.
nvd
CVE-2025-45862P3MEDIUMCVSS 6.5v4.0.0-b20230531.14042025-05-20
CVE-2025-45862 [MEDIUM] CWE-121 CVE-2025-45862: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacen TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface.
nvd
CVE-2025-45859P4MEDIUMCVSS 5.4v4.0.0-b20230531.14042025-05-13
CVE-2025-45859 [MEDIUM] CWE-120 CVE-2025-45859: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr pa TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.
nvd
CVE-2025-45864P4MEDIUMCVSS 5.4v4.0.0-b20230531.14042025-05-13
CVE-2025-45864 [MEDIUM] CWE-120 CVE-2025-45864: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolSt TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.
nvd
CVE-2025-45867P4MEDIUMCVSS 5.4v4.0.0-b20230531.14042025-05-13
CVE-2025-45867 [MEDIUM] CWE-121 CVE-2025-45867: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.
nvd
CVE-2025-55584P4MEDIUMCVSS 5.3v4.0.0-b20230531.14042025-08-18
CVE-2025-55584 [MEDIUM] CWE-1391 CVE-2025-55584: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.
nvd
CVE-2021-34218P4MEDIUMCVSS 5.3v1.1.1-b202008242021-08-20
CVE-2021-34218 [MEDIUM] CVE-2021-34218: Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows at Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.
nvd
CVE-2025-45866P4MEDIUMCVSS 5.4v4.0.0-b20230531.14042025-05-13
CVE-2025-45866 [MEDIUM] CWE-120 CVE-2025-45866: TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEn TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.
nvd
CVE-2021-34207P4MEDIUMCVSS 6.1v1.1.1-b202008242021-08-20
CVE-2021-34207 [MEDIUM] CWE-79 CVE-2021-34207: Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field.
nvd
CVE-2021-34223P4MEDIUMCVSS 6.1v1.1.1-b202008242021-08-20
CVE-2021-34223 [MEDIUM] CWE-79 CVE-2021-34223: Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.
nvd
CVE-2021-34220P4MEDIUMCVSS 6.1v1.1.1-b202008242021-08-20
CVE-2021-34220 [MEDIUM] CWE-79 CVE-2021-34220: Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Updat Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.
nvd
CVE-2021-34215P4MEDIUMCVSS 6.1v1.1.1-b202008242021-08-20
CVE-2021-34215 [MEDIUM] CWE-79 CVE-2021-34215: Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.
nvd