Product:

N302r_plus_firmware

(Totolink)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 3
Date Id Summary Products Score Patch Annotated
2025-06-05 CVE-2025-5671 A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B20201028. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. N302r_plus_firmware 8.8
2025-06-05 CVE-2025-5672 A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. N302r_plus_firmware 8.8
2020-12-09 CVE-2020-25499 TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router. A3002r_firmware, A3002ru\-V1_firmware, A3002ru\-V2_firmware, A702r\-V2_firmware, A702r\-V3_firmware, N100re\-V3_firmware, N150rt_firmware, N200re\-V3_firmware, N200re\-V4_firmware, N210re_firmware, N300rh\-V3_firmware, N300rt_firmware, N302r_plus_firmware 8.8