Totolink · Totolink A3002Ru · CVE-2025-55589
Name of the Vulnerable Software and Affected Versions:
TOTOLINK A3002R version 4.0.0-B20230531.1404
Description:
The TOTOLINK A3002R router firmware contains multiple OS command injection vulnerabilities. These vulnerabilities are located in the `/boafrm/formMapDelDevice` endpoint and can be triggered via the `macstr`, `bandstr`, and `clientoff` parameters.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.