cbcvebase.

Totolink A3002Ru Firmware vulnerabilities

49 known vulnerabilities affecting totolink/a3002ru_firmware.

Total CVEs
49
CISA KEV
0
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH29MEDIUM9LOW2

Vulnerabilities

Page 2 of 3
CVE-2025-4733P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-16
CVE-2025-4733 [HIGH] CWE-119 CVE-2025-4733: A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0 A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack may be initiated remotely. The exploit has be
nvd
CVE-2025-6337P2HIGHCVSS 8.8v3.0.0-b20230809.1615v4.0.0-b20230531.14042025-06-20
CVE-2025-6337 [HIGH] CWE-119 CVE-2025-6337: A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can b
nvd
CVE-2025-4833P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4833 [HIGH] CWE-119 CVE-2025-4833: A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This issue affects some unknown processing of the file /boafrm/formNtp of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been
nvd
CVE-2025-4830P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4830 [HIGH] CWE-119 CVE-2025-4830: A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A300 A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this issue is some unknown functionality of the file /boafrm/formSysCmd of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remo
nvd
CVE-2025-4823P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4823 [HIGH] CWE-119 CVE-2025-4823: A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been ra A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is the function submit-url of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been di
nvd
CVE-2025-4825P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4825 [HIGH] CWE-119 CVE-2025-4825: A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B202308 A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been discl
nvd
CVE-2025-4826P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4826 [HIGH] CWE-119 CVE-2025-4826: A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A300 A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely
nvd
CVE-2025-4730P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-16
CVE-2025-4730 [HIGH] CWE-119 CVE-2025-4730: A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel of the component HTTP POST Request Handler. The manipulation of the argument devicemac1 leads to buffer overflow. The attack may be launched remotely. The exploit
nvd
CVE-2018-13311P2CRITICALCVSS 9.8v1.0.82018-11-26
CVE-2018-13311 [CRITICAL] CWE-78 CVE-2018-13311: System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute s System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.
nvd
CVE-2025-6953P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-07-01
CVE-2025-6953 [HIGH] CWE-119 CVE-2025-6953: A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.161 A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been d
nvd
CVE-2025-6939P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-07-01
CVE-2025-6939 [HIGH] CWE-119 CVE-2025-6939: A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affe A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteSurvey of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed
nvd
CVE-2025-4834P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4834 [HIGH] CWE-119 CVE-2025-4834: A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been cl A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been classified as critical. Affected is an unknown function of the file /boafrm/formSetLg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit
nvd
CVE-2025-4835P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4835 [HIGH] CWE-119 CVE-2025-4835: A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been de A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of the argument redirect-url leads to buffer overflow. The attack can be launc
nvd
CVE-2025-4827P2HIGHCVSS 8.8v3.0.0-b20230809.16152025-05-17
CVE-2025-4827 [HIGH] CWE-119 CVE-2025-4827: A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3 A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exp
nvd
CVE-2026-26732P3HIGHCVSS 8.8v2.1.1-b20211108.14552026-02-17
CVE-2026-26732 [HIGH] CWE-787 CVE-2026-26732: TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via t TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter function.
nvd
CVE-2023-48859P3HIGHCVSS 8.8v2.0.0-b20190902.19582023-12-06
CVE-2023-48859 [HIGH] CWE-863 CVE-2023-48859: TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.
nvd
CVE-2022-35491P3CRITICALCVSS 9.8v3.0.0-b20220304.18042022-08-10
CVE-2022-35491 [CRITICAL] CWE-798 CVE-2022-35491: TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample. TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.
nvd
CVE-2024-34198P3CRITICALCVSS 9.8v2.1.1-b20230720.10112024-08-28
CVE-2024-34198 [CRITICAL] CWE-120 CVE-2024-34198: TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying an excessively long value for the wlan_ssid field, leading to a stack o
nvd
CVE-2025-6393P3HIGHCVSS 7.5v3.0.0-b20230809.16152025-06-21
CVE-2025-6393 [HIGH] CWE-119 CVE-2025-6393: A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0- A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads
nvd
CVE-2025-4729P3MEDIUMCVSS 6.3v3.0.0-b20230809.16152025-05-16
CVE-2025-4729 [MEDIUM] CWE-74 CVE-2025-4729: A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to command injection. The attack can be launched remotel
nvd
Totolink A3002Ru Firmware vulnerabilities | cvebase