TOTOLINK A3002RU是中国吉翁电子(TOTOLINK)公司的一款无线路由器产品。 TOTOLINK A3002RU 2.1.1-B20230720.1011版本存在代码注入漏洞,该漏洞源于对参数Comment的错误操作导致跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-5503 | 8.8 HIGH | TOTOLINK X15 formMapReboot stack-based overflow |
| CVE-2025-5515 | 6.3 MEDIUM | TOTOLINK X2000R formMapDel command injection |
| CVE-2025-5504 | 6.3 MEDIUM | TOTOLINK X2000R formWsc command injection |
| CVE-2025-5502 | 6.3 MEDIUM | TOTOLINK X15 formMapReboot command injection |
| CVE-2025-5543 | 2.4 LOW | TOTOLINK X2000R Parent Controls Page cross site scripting |
| CVE-2025-5542 | 2.4 LOW | TOTOLINK X2000R Virtual Server Page formPortFw cross site scripting |
| CVE-2025-5516 | 2.4 LOW | TOTOLINK X2000R URL Filtering Page formFilter cross site scripting |
| CVE-2025-5508 | 2.4 LOW | TOTOLINK A3002RU IP Port Filtering Page cross site scripting |
| CVE-2025-5507 | 2.4 LOW | TOTOLINK A3002RU MAC Filtering Page cross site scripting |
| CVE-2025-5505 | 2.4 LOW | TOTOLINK A3002RU Virtual Server Page formPortFw cross site scripting |
No comments yet