VendorsTOTOLINKa3002ru-v2all versions
Vulnerabilities

TOTOLINK A3002RU-V2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-25499
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
Published 2020-12-09 · Modified
9.0EPSS 0.043
CVE-2026-26731
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.
Published 2026-02-17 · Modified
8.8EPSS 0.005
CVE-2026-26732
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter function.
Published 2026-02-17 · Modified
8.8EPSS 0.003
CVE-2025-5508
TOTOLINK A3002RU IP Port Filtering Page cross site scripting
Published 2025-06-03 · Analyzed
4.8EPSS 0.004