A3002R
47 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for A3002R, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
A3002R CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 2 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 27 |
| 2025-06 | 7 |
| 2025-07 | 0 |
| 2025-08 | 8 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 47 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical7
- High28
- Medium11
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting A3002R.
- CVE-2025-55588TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS...7.5
- CVE-2025-55591TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.9.8
- CVE-2025-55590TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.6.5
- CVE-2025-55584TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.5.3
- CVE-2025-55589TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.6.5
- CVE-2025-55587TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Ser...7.5
- CVE-2025-55586TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) ...7.5
- CVE-2025-55585TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.6.5
- CVE-2025-6487TOTOLINK A3002R formRoute stack-based overflow8.8
- CVE-2025-6486TOTOLINK A3002R formWlanMultipleAP stack-based overflow8.8
- CVE-2025-6485TOTOLINK A3002R formWlSiteSurvey os command injection6.3
- CVE-2025-6393TOTOLINK A702R/A3002R/A3002RU/EX1200T HTTP POST Request formIPv6Addr buffer overflow8.8
- CVE-2025-6337TOTOLINK A3002R/A3002RU HTTP POST Request formTmultiAP buffer overflow8.8
- CVE-2025-6164TOTOLINK A3002R HTTP POST Request formMultiAP buffer overflow8.8
- CVE-2025-6149TOTOLINK A3002R HTTP POST Request formSysLog buffer overflow8.8
Product grouping is registry-driven, with AI assist and human review. How it works