Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jeong Yun Ho

#20036of 53,633
13Total CVSS
Vulnerabilities · 2
Medium
2
PT-2025-33685
6.5
2025-08-18
Totolink · Totolink A3002Ru · CVE-2025-55585
Name of the Vulnerable Software and Affected Versions: TOTOLINK A3002R version 4.0.0-B20230531.1404 Description: The TOTOLINK A3002R device was found to have an eval injection issue due to the use of the `eval()` function. This allows for potential code execution. Recommendations: Update to a newer version that does not utilize the `eval()` function.
PT-2025-33689
6.5
2025-08-18
Totolink · Totolink A3002Ru · CVE-2025-55589
Name of the Vulnerable Software and Affected Versions: TOTOLINK A3002R version 4.0.0-B20230531.1404 Description: The TOTOLINK A3002R router firmware contains multiple OS command injection vulnerabilities. These vulnerabilities are located in the `/boafrm/formMapDelDevice` endpoint and can be triggered via the `macstr`, `bandstr`, and `clientoff` parameters. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.