Vulnerabilities > Totolink > A3002R Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-20 | CVE-2021-34218 | Unspecified vulnerability in Totolink A3002R Firmware 1.1.1B20200824 Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter. | 5.3 |
2021-08-20 | CVE-2021-34220 | Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824 Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field. | 6.1 |
2021-08-20 | CVE-2021-34223 | Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824 Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field. | 6.1 |
2021-08-20 | CVE-2021-34228 | Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824 Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field. | 6.1 |
2020-12-09 | CVE-2020-25499 | Missing Authorization vulnerability in Totolink products TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. | 8.8 |