CVE Tools

A3002R

47 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for A3002R, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

A3002R CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
A3002R CVEs per month
MonthCVEs
2024-100
2024-110
2024-122
2025-010
2025-021
2025-031
2025-040
2025-0527
2025-067
2025-070
2025-088
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 47 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical715%
  • High2860%
  • Medium1123%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting A3002R.

  1. CVE-2025-55588TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS...7.5
  2. CVE-2025-55591TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.9.8
  3. CVE-2025-55590TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.6.5
  4. CVE-2025-55584TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.5.3
  5. CVE-2025-55589TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.6.5
  6. CVE-2025-55587TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Ser...7.5
  7. CVE-2025-55586TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) ...7.5
  8. CVE-2025-55585TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.6.5
  9. CVE-2025-6487TOTOLINK A3002R formRoute stack-based overflow8.8
  10. CVE-2025-6486TOTOLINK A3002R formWlanMultipleAP stack-based overflow8.8
  11. CVE-2025-6485TOTOLINK A3002R formWlSiteSurvey os command injection6.3
  12. CVE-2025-6393TOTOLINK A702R/A3002R/A3002RU/EX1200T HTTP POST Request formIPv6Addr buffer overflow8.8
  13. CVE-2025-6337TOTOLINK A3002R/A3002RU HTTP POST Request formTmultiAP buffer overflow8.8
  14. CVE-2025-6164TOTOLINK A3002R HTTP POST Request formMultiAP buffer overflow8.8
  15. CVE-2025-6149TOTOLINK A3002R HTTP POST Request formSysLog buffer overflow8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store