VendorsTOTOLINKa3002ru_firmwareall versions
Vulnerabilities

TOTOLINK A3002ru Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2018-13316
System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter.
Published 2018-11-27 · Modified
10.0EPSS 0.032
CVE-2018-13307
System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.
Published 2018-11-27 · Modified
10.0EPSS 0.032
CVE-2018-13314
System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.
Published 2018-11-27 · Modified
10.0EPSS 0.032
CVE-2018-13306
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.
Published 2018-11-27 · Modified
10.0EPSS 0.032
CVE-2018-13311
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.
Published 2018-11-26 · Modified
10.0EPSS 0.025
CVE-2019-19825
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The attacker can perform router actions via HTTP requests with Basic Authentication.) This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.
Published 2020-01-27 · Modified
9.8EPSS 0.296
CVE-2018-13315
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.
Published 2018-11-26 · Modified
9.8EPSS 0.016
CVE-2022-35491
TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.
Published 2022-08-09 · Modified
9.8EPSS 0.008
CVE-2024-34198
TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying an excessively long value for the wlan_ssid field, leading to a stack overflow. This can be further exploited to execute arbitrary commands or launch denial-of-service attacks.
Published 2024-08-28 · Analyzed
9.8EPSS 0.007
CVE-2019-19824
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.
Published 2020-01-27 · Modified
9.0EPSS 0.251
CVE-2025-6393
TOTOLINK A702R/A3002R/A3002RU/EX1200T HTTP POST Request formIPv6Addr buffer overflow
Published 2025-06-21 · Analyzed
9.0EPSS 0.010
CVE-2025-6148
TOTOLINK A3002RU HTTP POST Request formSysLog buffer overflow
Published 2025-06-17 · Analyzed
9.0EPSS 0.010
CVE-2025-6337
TOTOLINK A3002R/A3002RU HTTP POST Request formTmultiAP buffer overflow
Published 2025-06-20 · Analyzed
9.0EPSS 0.010
CVE-2025-6163
TOTOLINK A3002RU HTTP POST Request formMultiAP buffer overflow
Published 2025-06-17 · Analyzed
9.0EPSS 0.010
CVE-2025-6953
TOTOLINK A3002RU HTTP POST Request formParentControl buffer overflow
Published 2025-07-01 · Analyzed
9.0EPSS 0.009
CVE-2025-6939
TOTOLINK A3002RU HTTP POST Request formWlSiteSurvey buffer overflow
Published 2025-07-01 · Analyzed
9.0EPSS 0.009
CVE-2025-4832
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formDosCfg buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4831
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSiteSurveyProfile buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4834
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSetLg buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4833
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formNtp buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4835
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWlanRedirect buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4824
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWsc buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4825
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formDMZ buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4826
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWirelessTbl buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4829
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formStats sub_40BE30 buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4830
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSysCmd buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4827
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSaveConfig buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4823
TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formReflashClientTbl submit-url buffer overflow
Published 2025-05-17 · Analyzed
9.0EPSS 0.008
CVE-2025-4730
TOTOLINK A3002R/A3002RU HTTP POST Request formMapDel buffer overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.008
CVE-2025-4731
TOTOLINK A3002R/A3002RU HTTP POST Request formPortFw buffer overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.008
CVE-2025-4732
TOTOLINK A3002R/A3002RU HTTP POST Request formFilter buffer overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.008
CVE-2025-4733
TOTOLINK A3002R/A3002RU HTTP POST Request formIpQoS buffer overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.008
CVE-2023-48859
TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.
Published 2023-12-06 · Modified
8.8EPSS 0.012
CVE-2026-26736
TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function.
Published 2026-02-17 · Modified
8.8EPSS 0.005
CVE-2026-26731
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.
Published 2026-02-17 · Modified
8.8EPSS 0.005
CVE-2026-26732
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter function.
Published 2026-02-17 · Modified
8.8EPSS 0.003
CVE-2019-19822
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
Published 2020-01-27 · Modified
7.5EPSS 0.087
CVE-2019-19823
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.
Published 2020-01-27 · Modified
7.5EPSS 0.064
CVE-2025-4729
TOTOLINK A3002R/A3002RU HTTP POST Request formMapDelDevice command injection
Published 2025-05-15 · Analyzed
6.5EPSS 0.012
CVE-2018-13313
Admin Password returned in password.htm
Published 2020-02-24 · Modified
6.5EPSS 0.010
1 / 2Next →