VendorsTOTOLINKa3002ru_firmware1.0.8
Vulnerabilities

TOTOLINK A3002ru Firmware 1.0.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2018-13306
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.
Published 2018-11-27 · Modified
10.0EPSS 0.032
CVE-2018-13307
System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.
Published 2018-11-27 · Modified
10.0EPSS 0.032
CVE-2018-13314
System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.
Published 2018-11-27 · Modified
10.0EPSS 0.032
CVE-2018-13316
System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter.
Published 2018-11-27 · Modified
10.0EPSS 0.032
CVE-2018-13311
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.
Published 2018-11-26 · Modified
10.0EPSS 0.025
CVE-2018-13315
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.
Published 2018-11-26 · Modified
9.8EPSS 0.016
CVE-2018-13313
Admin Password returned in password.htm
Published 2020-02-24 · Modified
6.5EPSS 0.010
CVE-2018-13317
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.
Published 2018-11-26 · Modified
6.1EPSS 0.010
CVE-2018-13309
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.
Published 2018-11-26 · Modified
6.1EPSS 0.007
CVE-2018-13308
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.
Published 2018-11-26 · Modified
6.1EPSS 0.007
CVE-2018-13312
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.
Published 2018-11-26 · Modified
6.1EPSS 0.007
CVE-2018-13310
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.
Published 2018-11-26 · Modified
6.1EPSS 0.007