VendorsTOTOLINKa3002rall versions
Vulnerabilities

TOTOLINK A3002R

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2025-55586
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-08-18 · Analyzed
7.5EPSS 0.004
CVE-2025-55587
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-08-18 · Analyzed
7.5EPSS 0.004
CVE-2025-55588
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-08-18 · Analyzed
7.5EPSS 0.004
CVE-2025-6485
TOTOLINK A3002R formWlSiteSurvey os command injection
Published 2025-06-22 · Analyzed
6.5EPSS 0.091
CVE-2025-4729
TOTOLINK A3002R/A3002RU HTTP POST Request formMapDelDevice command injection
Published 2025-05-15 · Analyzed
6.5EPSS 0.012
CVE-2025-55589
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.
Published 2025-08-18 · Analyzed
6.5EPSS 0.011
CVE-2025-55590
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.
Published 2025-08-18 · Analyzed
6.5EPSS 0.008
CVE-2025-45862
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface.
Published 2025-05-20 · Analyzed
6.5EPSS 0.003
CVE-2025-55585
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.
Published 2025-08-18 · Analyzed
6.5EPSS 0.003
CVE-2021-34228
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.
Published 2021-08-20 · Modified
6.1EPSS 0.292
CVE-2021-34207
Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field.
Published 2021-08-20 · Modified
6.1EPSS 0.007
CVE-2021-34215
Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.
Published 2021-08-20 · Modified
6.1EPSS 0.007
CVE-2021-34220
Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.
Published 2021-08-20 · Modified
6.1EPSS 0.007
CVE-2021-34223
Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.
Published 2021-08-20 · Modified
6.1EPSS 0.007
CVE-2025-45859
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.
Published 2025-05-13 · Analyzed
5.4EPSS 0.050
CVE-2025-45864
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.
Published 2025-05-13 · Analyzed
5.4EPSS 0.049
CVE-2025-45867
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.
Published 2025-05-13 · Analyzed
5.4EPSS 0.049
CVE-2025-45866
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.
Published 2025-05-13 · Analyzed
5.4EPSS 0.003
CVE-2021-34218
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.
Published 2021-08-20 · Modified
5.3EPSS 0.008
CVE-2025-55584
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.
Published 2025-08-18 · Analyzed
5.3EPSS 0.003
CVE-2025-4852
TOTOLINK A3002R VPN Page cross site scripting
Published 2025-05-18 · Analyzed
4.8EPSS 0.004
← Prev2 / 2