VYPR

A3002RU

by Totolink

CVEs (93)

  • CVE-2018-13310MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.

  • CVE-2018-13309MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.

  • CVE-2018-13308MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.

  • CVE-2025-45867MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.05

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.

  • CVE-2025-45866MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.00

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.

  • CVE-2025-45864MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.05

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.

  • CVE-2025-45859MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.05

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.

  • CVE-2025-55584MedAug 18, 2025
    risk 0.34cvss 5.3epss 0.00

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.

  • CVE-2025-5508LowJun 3, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IP Port Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack…

  • CVE-2025-5507LowJun 3, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component MAC Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The…

  • CVE-2025-5506LowJun 3, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as problematic. Affected is an unknown function of the component NAT Mapping Page. The manipulation of the argument Comment leads to cross site scripting. It is possible to launch the…

  • CVE-2025-5505LowJun 3, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site…

  • CVE-2025-4852LowMay 18, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability, which was classified as problematic, has been found in TOTOLINK A3002R 2.1.1-B20230720.1011. This issue affects some unknown processing of the component VPN Page. The manipulation of the argument Comment leads to cross site scripting. The attack may be initiated…

Page 5 of 5