cbcvebase.

Totolink A3002Ru vulnerabilities

27 known vulnerabilities affecting totolink/a3002ru.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH22MEDIUM3LOW2

Vulnerabilities

Page 2 of 2
CVE-2025-4835P2HIGHCVSS 8.8v3.0.0-B20230809.16152025-05-17
CVE-2025-4835 [HIGH] CWE-119 CVE-2025-4835: A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been de A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of the argument redirect-url leads to buffer overflow. The attack can be launc
nvd
CVE-2025-6393P3HIGHCVSS 7.5v3.0.0-B20230809.1615v4.0.0-B20230531.1404+2 more2025-06-21
CVE-2025-6393 [HIGH] CWE-119 CVE-2025-6393: A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0- A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads
nvd
CVE-2025-4729P3MEDIUMCVSS 6.3v3.0.0-B20230809.16152025-05-16
CVE-2025-4729 [MEDIUM] CWE-74 CVE-2025-4729: A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to command injection. The attack can be launched remotel
nvd
CVE-2025-5506P4MEDIUMCVSS 5.4v2.1.1-B20230720.10112025-06-03
CVE-2025-5506 [MEDIUM] CWE-79 CVE-2025-5506: A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as proble A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as problematic. Affected is an unknown function of the component NAT Mapping Page. The manipulation of the argument Comment leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-5507P4MEDIUMCVSS 5.4v2.1.1-B20230720.10112025-06-03
CVE-2025-5507 [MEDIUM] CWE-79 CVE-2025-5507: A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problema A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component MAC Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public
nvd
CVE-2025-5508P4LOWCVSS 3.4v2.1.1-B20230720.10112025-06-03
CVE-2025-5508 [LOW] CWE-79 CVE-2025-5508: A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IP Port Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may
nvd
CVE-2025-5505P4LOWCVSS 2.4v2.1.1-B20230720.10112025-06-03
CVE-2025-5505 [LOW] CWE-79 CVE-2025-5505: A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. Th A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed t
nvd
Totolink A3002Ru vulnerabilities | cvebase