Vulnerabilities > Totolink > A3002R Firmware

DATE CVE VULNERABILITY TITLE RISK
2021-08-20 CVE-2021-34223 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.
network
low complexity
totolink CWE-79
6.1
2021-08-20 CVE-2021-34228 Cross-site Scripting vulnerability in Totolink A3002R Firmware 1.1.1B20200824
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.
network
low complexity
totolink CWE-79
6.1
2020-12-09 CVE-2020-25499 Missing Authorization vulnerability in Totolink products
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'.
network
low complexity
totolink CWE-862
8.8