Vulnerabilities > Totolink > A3002R Firmware > 1.1.1.b20200824

DATE CVE VULNERABILITY TITLE RISK
2024-08-28 CVE-2024-34195 Out-of-bounds Write vulnerability in Totolink A3002R Firmware 1.1.1B20200824
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow.
network
low complexity
totolink CWE-787
critical
9.8
2021-08-20 CVE-2021-34207 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field.
network
low complexity
totolink CWE-79
6.1
2021-08-20 CVE-2021-34215 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.
network
low complexity
totolink CWE-79
6.1
2021-08-20 CVE-2021-34218 Unspecified vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.
network
low complexity
totolink
5.3
2021-08-20 CVE-2021-34220 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.
network
low complexity
totolink CWE-79
6.1
2021-08-20 CVE-2021-34223 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.
network
low complexity
totolink CWE-79
6.1
2021-08-20 CVE-2021-34228 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.
network
low complexity
totolink CWE-79
6.1
2020-12-09 CVE-2020-25499 Missing Authorization vulnerability in Totolink products
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'.
network
low complexity
totolink CWE-862
8.8