Vulnerabilities > Totolink > A3002R Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-05-13 | CVE-2025-45861 | Classic Buffer Overflow vulnerability in Totolink A3002R Firmware 4.0.0B20230531.1404 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface. | 9.8 |
2025-05-13 | CVE-2025-45865 | Classic Buffer Overflow vulnerability in Totolink A3002R Firmware 4.0.0B20230531.1404 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface. | 9.8 |
2024-08-28 | CVE-2024-34195 | Out-of-bounds Write vulnerability in Totolink A3002R Firmware 1.1.1B20200824 TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. | 9.8 |
2024-08-12 | CVE-2024-42520 | Classic Buffer Overflow vulnerability in Totolink A3002R Firmware 4.0.0B20230531.1404 TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl. | 9.8 |
2022-09-06 | CVE-2022-40109 | Incorrect Default Permissions vulnerability in Totolink A3002R Firmware 1.1.1B20200824.0128 TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa. | 9.8 |
2022-09-06 | CVE-2022-40110 | Classic Buffer Overflow vulnerability in Totolink A3002R Firmware 1.1.1B20200824.0128 TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa. | 7.5 |
2022-09-06 | CVE-2022-40111 | Use of Hard-coded Credentials vulnerability in Totolink A3002R Firmware 1.1.1B20200824.0128 In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware. | 9.8 |
2022-09-06 | CVE-2022-40112 | Classic Buffer Overflow vulnerability in Totolink A3002R Firmware 1.1.1B20200824.0128 TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in binary /bin/boa. | 7.5 |
2021-08-20 | CVE-2021-34207 | Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824 Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field. | 6.1 |
2021-08-20 | CVE-2021-34215 | Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824 Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field. | 6.1 |