PT-2025-23637 · Totolink · Totolink A3002Ru
Lcyf-Fizz
·
Published
2025-05-26
·
Updated
2025-06-03
·
CVE-2025-5507
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TOTOLINK A3002RU version 2.1.1-B20230720.1011
Description
A vulnerability was found in the MAC Filtering Page component of the affected software. The issue arises from the manipulation of the
Comment argument, leading to cross-site scripting. This can be exploited remotely. The vendor was contacted about the disclosure but did not respond.Recommendations
For TOTOLINK A3002RU version 2.1.1-B20230720.1011, as a temporary workaround, consider restricting access to the MAC Filtering Page or disabling the functionality that allows manipulation of the
Comment argument until a patch is available. Avoid using the Comment argument in the affected component to minimize the risk of exploitation.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Totolink A3002Ru