Totolink N302R Plus Firmware vulnerabilities

3 known vulnerabilities affecting totolink/n302r_plus_firmware.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH3

Vulnerabilities

Page 1 of 1
CVE-2025-5672HIGHCVSS 8.7fixed in 3.4.0-b202010282025-06-05
CVE-2025-5672 [HIGH] CWE-119 CVE-2025-5672: A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critic A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument url leads to buffer overflow. The attack can be launched remotely. The exploit has b
nvd
CVE-2025-5671HIGHCVSS 8.7fixed in 3.4.0-b202010282025-06-05
CVE-2025-5671 [HIGH] CWE-119 CVE-2025-5671: A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B202 A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B20201028. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been di
nvd
CVE-2020-25499HIGHCVSS 8.8Exploitedfixed in 3.4.0-b20201028.22242020-12-09
CVE-2020-25499 [HIGH] CWE-78 CVE-2020-25499: TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
nvd