Totolink A3002Ru Firmware vulnerabilities
49 known vulnerabilities affecting totolink/a3002ru_firmware.
Total CVEs
49
CISA KEV
0
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH29MEDIUM9LOW2
Vulnerabilities
Page 3 of 3
CVE-2018-13313P4MEDIUMCVSS 6.5v1.0.82020-02-24
CVE-2018-13313 [MEDIUM] CWE-922 CVE-2018-13313: In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account n
In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user knows their current password before allowing them to change their password. However, this JavaScript contains the current user’s password in plaintext.
nvd
CVE-2025-5506P4MEDIUMCVSS 5.4v2.1.1-b20230720.10112025-06-03
CVE-2025-5506 [MEDIUM] CWE-79 CVE-2025-5506: A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as proble
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as problematic. Affected is an unknown function of the component NAT Mapping Page. The manipulation of the argument Comment leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-5507P4MEDIUMCVSS 5.4v2.1.1-b20230720.10112025-06-03
CVE-2025-5507 [MEDIUM] CWE-79 CVE-2025-5507: A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problema
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component MAC Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public
nvd
CVE-2018-13309P4MEDIUMCVSS 6.1v1.0.82018-11-26
CVE-2018-13309 [MEDIUM] CWE-79 CVE-2018-13309: Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute a
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.
nvd
CVE-2018-13310P4MEDIUMCVSS 6.1v1.0.82018-11-26
CVE-2018-13310 [MEDIUM] CWE-79 CVE-2018-13310: Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute a
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.
nvd
CVE-2018-13312P4MEDIUMCVSS 6.1v1.0.82018-11-26
CVE-2018-13312 [MEDIUM] CWE-79 CVE-2018-13312: Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.
nvd
CVE-2018-13308P4MEDIUMCVSS 6.1v1.0.82018-11-26
CVE-2018-13308 [MEDIUM] CWE-79 CVE-2018-13308: Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.
nvd
CVE-2025-5508P4LOWCVSS 3.4v2.1.1-b20230720.10112025-06-03
CVE-2025-5508 [LOW] CWE-79 CVE-2025-5508: A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IP Port Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may
nvd
CVE-2025-5505P4LOWCVSS 2.4v2.1.1-b20230720.10112025-06-03
CVE-2025-5505 [LOW] CWE-79 CVE-2025-5505: A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. Th
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed t
nvd
← Previous3 / 3