PT-2025-23637 · Totolink · Totolink A3002Ru

·

CVE-2025-5507

·

Published

2025-05-26

·

Updated

2025-06-03

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK A3002RU version 2.1.1-B20230720.1011
Description A vulnerability was found in the MAC Filtering Page component of the affected software. The issue arises from the manipulation of the Comment argument, leading to cross-site scripting. This can be exploited remotely. The vendor was contacted about the disclosure but did not respond.
Recommendations For TOTOLINK A3002RU version 2.1.1-B20230720.1011, as a temporary workaround, consider restricting access to the MAC Filtering Page or disabling the functionality that allows manipulation of the Comment argument until a patch is available. Avoid using the Comment argument in the affected component to minimize the risk of exploitation.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06476
CVE-2025-5507

Affected Products

Totolink A3002Ru