Product:

A3002r_firmware

(Totolink)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 55
Date Id Summary Products Score Patch Annotated
2025-05-17 CVE-2025-4834 A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been classified as critical. Affected is an unknown function of the file /boafrm/formSetLg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. A3002r_firmware, A3002ru_firmware, A702r_firmware 8.8
2025-05-20 CVE-2025-45862 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface. A3002r_firmware N/A
2025-05-20 CVE-2025-45862 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface. A3002r_firmware N/A
2025-05-13 CVE-2025-45861 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface. A3002r_firmware 9.8
2025-05-13 CVE-2025-45865 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface. A3002r_firmware 9.8
2025-05-13 CVE-2025-45861 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface. A3002r_firmware 9.8
2025-05-13 CVE-2025-45865 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface. A3002r_firmware 9.8
2020-12-09 CVE-2020-25499 TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router. A3002r_firmware, A3002ru\-V1_firmware, A3002ru\-V2_firmware, A702r\-V2_firmware, A702r\-V3_firmware, N100re\-V3_firmware, N150rt_firmware, N200re\-V3_firmware, N200re\-V4_firmware, N210re_firmware, N300rh\-V3_firmware, N300rt_firmware, N302r_plus_firmware 8.8
2021-08-20 CVE-2021-34207 Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field. A3002r_firmware 6.1
2021-08-20 CVE-2021-34215 Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field. A3002r_firmware 6.1