PT-2025-23637 · Totolink · Totolink A3002Ru

Lcyf-Fizz

·

Published

2025-05-26

·

Updated

2025-06-03

·

CVE-2025-5507

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK A3002RU version 2.1.1-B20230720.1011
Description A vulnerability was found in the MAC Filtering Page component of the affected software. The issue arises from the manipulation of the Comment argument, leading to cross-site scripting. This can be exploited remotely. The vendor was contacted about the disclosure but did not respond.
Recommendations For TOTOLINK A3002RU version 2.1.1-B20230720.1011, as a temporary workaround, consider restricting access to the MAC Filtering Page or disabling the functionality that allows manipulation of the Comment argument until a patch is available. Avoid using the Comment argument in the affected component to minimize the risk of exploitation.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06476
CVE-2025-5507

Affected Products

Totolink A3002Ru