Vulnerabilities > Totolink > A3002R Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-28 CVE-2024-34195 Out-of-bounds Write vulnerability in Totolink A3002R Firmware 1.1.1B20200824
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow.
network
low complexity
totolink CWE-787
critical
9.8
2024-08-12 CVE-2024-42520 Classic Buffer Overflow vulnerability in Totolink A3002R Firmware 4.0.0B20230531.1404
TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.
network
low complexity
totolink CWE-120
critical
9.8
2022-09-06 CVE-2022-40111 Use of Hard-coded Credentials vulnerability in Totolink A3002R Firmware 1.1.1B20200824.0128
In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.
network
low complexity
totolink CWE-798
critical
9.8
2022-09-06 CVE-2022-40109 Incorrect Default Permissions vulnerability in Totolink A3002R Firmware 1.1.1B20200824.0128
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.
network
low complexity
totolink CWE-276
critical
9.8