VendorsTOTOLINKa3002r_firmware4.0.0-b20230531.1404
Vulnerabilities

TOTOLINK A3002R Firmware 4.0.0-b20230531.1404

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2025-45858
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.
Published 2025-05-13 · Analyzed
9.8EPSS 0.107
CVE-2025-25579
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
Published 2025-03-28 · Analyzed
9.8EPSS 0.104
CVE-2025-55591
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.
Published 2025-08-18 · Analyzed
9.8EPSS 0.076
CVE-2024-42520
TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.
Published 2024-08-12 · Modified
9.8EPSS 0.006
CVE-2025-45865
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.
Published 2025-05-13 · Analyzed
9.8EPSS 0.006
CVE-2025-45861
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.
Published 2025-05-13 · Analyzed
9.8EPSS 0.006
CVE-2025-45863
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.
Published 2025-05-13 · Analyzed
9.8EPSS 0.006
CVE-2025-6393
TOTOLINK A702R/A3002R/A3002RU/EX1200T HTTP POST Request formIPv6Addr buffer overflow
Published 2025-06-21 · Analyzed
9.0EPSS 0.010
CVE-2025-6149
TOTOLINK A3002R HTTP POST Request formSysLog buffer overflow
Published 2025-06-17 · Analyzed
9.0EPSS 0.010
CVE-2025-6337
TOTOLINK A3002R/A3002RU HTTP POST Request formTmultiAP buffer overflow
Published 2025-06-20 · Analyzed
9.0EPSS 0.010
CVE-2025-6164
TOTOLINK A3002R HTTP POST Request formMultiAP buffer overflow
Published 2025-06-17 · Analyzed
9.0EPSS 0.010
CVE-2024-54907
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
Published 2024-12-26 · Analyzed
8.8EPSS 0.011
CVE-2024-33820
Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow.
Published 2024-05-01 · Analyzed
7.5EPSS 0.006
CVE-2025-55587
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-08-18 · Analyzed
7.5EPSS 0.004
CVE-2025-55588
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-08-18 · Analyzed
7.5EPSS 0.004
CVE-2025-55586
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-08-18 · Analyzed
7.5EPSS 0.004
CVE-2025-55589
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.
Published 2025-08-18 · Analyzed
6.5EPSS 0.011
CVE-2025-55590
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.
Published 2025-08-18 · Analyzed
6.5EPSS 0.008
CVE-2025-45862
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface.
Published 2025-05-20 · Analyzed
6.5EPSS 0.003
CVE-2025-55585
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.
Published 2025-08-18 · Analyzed
6.5EPSS 0.003
CVE-2025-45859
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.
Published 2025-05-13 · Analyzed
5.4EPSS 0.050
CVE-2025-45867
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.
Published 2025-05-13 · Analyzed
5.4EPSS 0.049
CVE-2025-45864
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.
Published 2025-05-13 · Analyzed
5.4EPSS 0.049
CVE-2025-45866
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.
Published 2025-05-13 · Analyzed
5.4EPSS 0.003
CVE-2025-55584
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.
Published 2025-08-18 · Analyzed
5.3EPSS 0.003