📦 A3002ru Firmware

by Totolink

🔍 What is A3002ru Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-34198

CRITICAL CVSS 9.8 Aug 28, 2024

This vulnerability allows attackers to execute arbitrary code or cause denial-of-service on TOTOLINK AC1200 routers by sending specially crafted HTTP requests with an overly long SSID field. It affect...

CVE-2026-26732

HIGH CVSS 8.8 Feb 17, 2026

This CVE describes a stack-based buffer overflow vulnerability in TOTOLINK A3002RU routers. Attackers can exploit this by sending specially crafted vpnUser or vpnPassword parameters to the formFilter ...

CVE-2025-6953

HIGH CVSS 8.8 Jul 1, 2025

This critical vulnerability in TOTOLINK A3002RU routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST request handler. Attackers can exploit this by manipula...

CVE-2025-6939

HIGH CVSS 8.8 Jul 1, 2025

A critical buffer overflow vulnerability in TOTOLINK A3002RU routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formWlSiteSurvey e...

CVE-2025-6393

HIGH CVSS 8.8 Jun 21, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formIPv6Addr endpoint. ...

CVE-2025-6337

HIGH CVSS 8.8 Jun 20, 2025

A critical buffer overflow vulnerability in TOTOLINK A3002R and A3002RU routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formTmu...

CVE-2025-4835

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formWlanRedirect endpoi...

CVE-2025-4834

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formSetLg endpoint. Att...

CVE-2025-4832

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formDosCfg endpoint. Th...

CVE-2025-4830

HIGH CVSS 8.8 May 17, 2025

This critical vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST request handler. Attackers can exploit this by manipulating the...

CVE-2025-4827

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the vulnerable endpoint. Attackers ...

CVE-2025-4823

HIGH CVSS 8.8 May 17, 2025

This critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the vulnerable submit-url function....

CVE-2025-4825

HIGH CVSS 8.8 May 17, 2025

A critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formDMZ endpoint. This aff...

CVE-2025-4733

HIGH CVSS 8.8 May 16, 2025

A critical buffer overflow vulnerability in TOTOLINK A3002R and A3002RU routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formIpQ...

CVE-2025-4730

HIGH CVSS 8.8 May 16, 2025

This critical buffer overflow vulnerability in TOTOLINK A3002R/A3002RU routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formMapD...

CVE-2025-4729

MEDIUM CVSS 6.3 May 16, 2025

This critical vulnerability in TOTOLINK A3002R and A3002RU routers allows remote attackers to execute arbitrary commands via command injection in the HTTP POST request handler. Attackers can exploit t...