Vulnerabilities (CVE)

Filtered by vendor Totolink Subscribe
Filtered by product A3002r
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34223 1 Totolink 2 A3002r, A3002r Firmware 2021-08-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field.
CVE-2021-34220 1 Totolink 2 A3002r, A3002r Firmware 2021-08-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.
CVE-2021-34218 1 Totolink 2 A3002r, A3002r Firmware 2021-08-26 5.0 MEDIUM 5.3 MEDIUM
Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter.
CVE-2021-34215 1 Totolink 2 A3002r, A3002r Firmware 2021-08-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field.
CVE-2021-34207 1 Totolink 2 A3002r, A3002r Firmware 2021-08-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field.
CVE-2021-34228 1 Totolink 2 A3002r, A3002r Firmware 2021-08-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field.