📦 A3002r Firmware

by Totolink

🔍 What is A3002r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-55591

CRITICAL CVSS 9.8 Aug 18, 2025

This critical command injection vulnerability in TOTOLINK-A3002R routers allows attackers to execute arbitrary system commands via the devicemac parameter. Attackers can gain full control of affected ...

CVE-2025-45863

CRITICAL CVSS 9.8 May 13, 2025

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3002R routers via a buffer overflow in the formMapDelDevice interface. Attackers can exploit this by sending specially...

CVE-2025-45861

CRITICAL CVSS 9.8 May 13, 2025

This CVE describes a critical buffer overflow vulnerability in TOTOLINK A3002R routers that allows remote attackers to execute arbitrary code or cause denial of service. The vulnerability affects rout...

CVE-2025-45858

CRITICAL CVSS 9.8 May 13, 2025

This CVE describes a command injection vulnerability in TOTOLINK A3002R routers that allows attackers to execute arbitrary commands on the device. The vulnerability exists in the FUN_00459fdc function...

CVE-2025-25579

CRITICAL CVSS 9.8 Mar 28, 2025

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A3002R routers via command injection in the bandstr parameter of the /bin/boa service. Attackers can gain full cont...

CVE-2025-55588

HIGH CVSS 7.5 Aug 18, 2025

This buffer overflow vulnerability in TOTOLINK A3002R routers allows attackers to cause Denial of Service by sending specially crafted input to the fw_ip parameter. The vulnerability affects TOTOLINK ...

CVE-2025-55586

HIGH CVSS 7.5 Aug 18, 2025

This CVE describes a buffer overflow vulnerability in the TOTOLINK A3002R router's web interface. Attackers can send specially crafted requests to the /boafrm/formFilter endpoint to cause a denial of ...

CVE-2025-6486

HIGH CVSS 8.8 Jun 22, 2025

This critical vulnerability in TOTOLINK A3002R routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formWlanMultipleAP function. Attackers can exploit thi...

CVE-2025-6393

HIGH CVSS 8.8 Jun 21, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formIPv6Addr endpoint. ...

CVE-2025-6337

HIGH CVSS 8.8 Jun 20, 2025

A critical buffer overflow vulnerability in TOTOLINK A3002R and A3002RU routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formTmu...

CVE-2025-6164

HIGH CVSS 8.8 Jun 17, 2025

A critical buffer overflow vulnerability in TOTOLINK A3002R routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formMultiAP endpoin...

CVE-2025-6149

HIGH CVSS 8.8 Jun 17, 2025

A critical buffer overflow vulnerability in TOTOLINK A3002R routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formSysLog endpoint...

CVE-2025-4835

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formWlanRedirect endpoi...

CVE-2025-4834

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formSetLg endpoint. Att...

CVE-2025-4832

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formDosCfg endpoint. Th...

CVE-2025-4830

HIGH CVSS 8.8 May 17, 2025

This critical vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST request handler. Attackers can exploit this by manipulating the...

CVE-2025-4827

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the vulnerable endpoint. Attackers ...

CVE-2025-4823

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the vulnerable submit-url function....

CVE-2025-4825

HIGH CVSS 8.8 May 17, 2025

A critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formDMZ endpoint. This aff...

CVE-2025-4733

HIGH CVSS 8.8 May 16, 2025

A critical buffer overflow vulnerability in TOTOLINK A3002R and A3002RU routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formIpQ...

CVE-2025-4730

HIGH CVSS 8.8 May 16, 2025

This critical buffer overflow vulnerability in TOTOLINK A3002R/A3002RU routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formMapD...

CVE-2025-25610

HIGH CVSS 8.0 Feb 28, 2025

This CVE describes a buffer overflow vulnerability in TOTOlink A3002R routers that allows attackers to execute arbitrary code by sending specially crafted requests to the formIpv6Setup interface. The ...

CVE-2025-25635

HIGH CVSS 8.0 Feb 28, 2025

This CVE describes a buffer overflow vulnerability in TOTOlink A3002R routers, caused by improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface. It allows attackers to po...

CVE-2025-25609

HIGH CVSS 8.0 Feb 28, 2025

This buffer overflow vulnerability in TOTOlink A3002R routers allows attackers to execute arbitrary code by sending specially crafted requests to the formIpv6Setup interface. The vulnerability affects...

CVE-2024-54907

HIGH CVSS 8.8 Dec 26, 2024

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3002R routers via the formWsc function in the /bin/boa web server. Attackers can take full control of affected devices...

CVE-2025-55590

MEDIUM CVSS 6.5 Aug 18, 2025

This CVE describes a command injection vulnerability in TOTOLINK A3002R routers via the bupload.html component. Attackers can execute arbitrary commands on affected devices, potentially compromising t...

CVE-2025-55585

MEDIUM CVSS 6.5 Aug 18, 2025

This CVE describes an eval injection vulnerability in TOTOLINK A3002R routers that allows attackers to execute arbitrary code by manipulating input to the eval() function. This affects users running t...

CVE-2025-6485

MEDIUM CVSS 6.3 Jun 22, 2025

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK A3002R routers by manipulating the wlanif parameter in the formWlSiteSurvey function. Att...

CVE-2025-45862

MEDIUM CVSS 6.5 May 20, 2025

This CVE describes a buffer overflow vulnerability in TOTOLINK A3002R routers via the interfacenameds parameter in the formDhcpv6s interface. Attackers can exploit this to execute arbitrary code or cr...

CVE-2025-4729

MEDIUM CVSS 6.3 May 16, 2025

This critical vulnerability in TOTOLINK A3002R and A3002RU routers allows remote attackers to execute arbitrary commands via command injection in the HTTP POST request handler. Attackers can exploit t...

CVE-2025-45864

MEDIUM CVSS 5.4 May 13, 2025

This CVE describes a buffer overflow vulnerability in TOTOLINK A3002R routers via the addrPoolStart parameter in the formDhcpv6s interface. Attackers could potentially execute arbitrary code or crash ...

CVE-2025-45867

MEDIUM CVSS 5.4 May 13, 2025

This CVE describes a buffer overflow vulnerability in TOTOLINK A3002R routers via the static_dns1 parameter in the formIpv6Setup interface. Attackers can exploit this to potentially execute arbitrary ...