Metrics
Affected Vendors & Products
Tue, 17 Jun 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Totolink
Totolink a3002ru Totolink a3002ru Firmware |
|
CPEs | cpe:2.3:h:totolink:a3002ru:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3002ru_firmware:2.1.1-b20230720.1011:*:*:*:*:*:*:* |
|
Vendors & Products |
Totolink
Totolink a3002ru Totolink a3002ru Firmware |
Wed, 04 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 03 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | TOTOLINK A3002RU Virtual Server Page formPortFw cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-03T15:00:20.068Z
Updated: 2025-06-04T20:29:55.827Z
Reserved: 2025-06-03T05:48:09.772Z
Link: CVE-2025-5505

Updated: 2025-06-04T20:29:51.855Z

Status : Analyzed
Published: 2025-06-03T15:16:00.717
Modified: 2025-06-17T20:40:34.987
Link: CVE-2025-5505

No data.