VYPR

A3002RU

by Totolink

CVEs (93)

  • CVE-2019-19825CriJan 27, 2020
    risk 0.66cvss 9.8epss 0.30

    On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The…

  • CVE-2025-25579CriMar 28, 2025
    risk 0.65cvss 9.8epss 0.10

    TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.

  • CVE-2025-55591CriAug 18, 2025
    risk 0.64cvss 9.8epss 0.07

    TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.

  • CVE-2025-45863CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.

  • CVE-2025-45865CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.

  • CVE-2025-45861CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.

  • CVE-2025-45858CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.11

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.

  • CVE-2024-34195CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversight leads to potential buffer overflow…

  • CVE-2024-34198CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying…

  • CVE-2024-42520CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.

  • CVE-2022-40111CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.

  • CVE-2022-40109CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.

  • CVE-2022-35491CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.

  • CVE-2018-13316CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter.

  • CVE-2018-13314CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.

  • CVE-2018-13307CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.

  • CVE-2018-13306CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.

  • CVE-2018-13315CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.02

    Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.

  • CVE-2018-13311CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.

  • CVE-2019-19824HigJan 27, 2020
    risk 0.59cvss 8.8epss 0.25

    On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects…

Page 1 of 5