VendorsTOTOLINKa3002rall versions
Vulnerabilities

TOTOLINK A3002R

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2025-45858
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.
Published 2025-05-13 · Analyzed
9.8EPSS 0.107
CVE-2025-25579
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
Published 2025-03-28 · Analyzed
9.8EPSS 0.104
CVE-2025-55591
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.
Published 2025-08-18 · Analyzed
9.8EPSS 0.076
CVE-2024-34195
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversight leads to potential buffer overflow under specific circumstances. For instance, by invoking the formWlanRedirect function with specific parameters to alter wlan_idx's value and subsequently invoking the formWlEncrypt function, an attacker can trigger buffer overflow, enabling arbitrary command execution or denial of service attacks.
Published 2024-08-28 · Analyzed
9.8EPSS 0.009
CVE-2022-40111
In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.
Published 2022-09-06 · Modified
9.8EPSS 0.009
CVE-2022-40109
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.
Published 2022-09-06 · Modified
9.8EPSS 0.009
CVE-2024-42520
TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.
Published 2024-08-12 · Modified
9.8EPSS 0.006
CVE-2025-45865
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.
Published 2025-05-13 · Analyzed
9.8EPSS 0.006
CVE-2025-45863
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.
Published 2025-05-13 · Analyzed
9.8EPSS 0.006
CVE-2025-45861
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.
Published 2025-05-13 · Analyzed
9.8EPSS 0.006
CVE-2020-25499
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
Published 2020-12-09 · Modified
9.0EPSS 0.043
CVE-2025-6393
TOTOLINK A702R/A3002R/A3002RU/EX1200T HTTP POST Request formIPv6Addr buffer overflow
Published 2025-06-21 · Analyzed
9.0EPSS 0.010
CVE-2025-6149
TOTOLINK A3002R HTTP POST Request formSysLog buffer overflow
Published 2025-06-17 · Analyzed
9.0EPSS 0.010
CVE-2025-6486
TOTOLINK A3002R formWlanMultipleAP stack-based overflow
Published 2025-06-22 · Analyzed
9.0EPSS 0.010
CVE-2025-6487
TOTOLINK A3002R formRoute stack-based overflow
Published 2025-06-22 · Analyzed
9.0EPSS 0.010
CVE-2025-6337
TOTOLINK A3002R/A3002RU HTTP POST Request formTmultiAP buffer overflow
Published 2025-06-20 · Analyzed
9.0EPSS 0.010
CVE-2025-6164
TOTOLINK A3002R HTTP POST Request formMultiAP buffer overflow
Published 2025-06-17 · Analyzed
9.0EPSS 0.010
CVE-2025-4831
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSiteSurveyProfile buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4834
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSetLg buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4835
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWlanRedirect buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4833
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formNtp buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4832
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formDosCfg buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4823
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formReflashClientTbl submit-url buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4824
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWsc buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4825
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formDMZ buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4826
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWirelessTbl buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4827
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSaveConfig buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4829
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formStats sub_40BE30 buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4830
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSysCmd buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4733
TOTOLINK A3002R/A3002RU HTTP POST Request formIpQoS buffer overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.008
CVE-2025-4730
TOTOLINK A3002R/A3002RU HTTP POST Request formMapDel buffer overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.008
CVE-2025-4731
TOTOLINK A3002R/A3002RU HTTP POST Request formPortFw buffer overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.008
CVE-2025-4732
TOTOLINK A3002R/A3002RU HTTP POST Request formFilter buffer overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.008
CVE-2024-54907
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
Published 2024-12-26 · Analyzed
8.8EPSS 0.011
CVE-2025-25635
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.
Published 2025-02-28 · Analyzed
8.0EPSS 0.004
CVE-2025-25609
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa
Published 2025-02-28 · Analyzed
8.0EPSS 0.003
CVE-2025-25610
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.
Published 2025-02-28 · Analyzed
8.0EPSS 0.003
CVE-2022-40110
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa.
Published 2022-09-06 · Modified
7.5EPSS 0.008
CVE-2022-40112
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in binary /bin/boa.
Published 2022-09-06 · Modified
7.5EPSS 0.008
CVE-2024-33820
Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow.
Published 2024-05-01 · Analyzed
7.5EPSS 0.006
1 / 2Next →