TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.
2025-08-18T20:15:31.563
2025-08-21T14:11:06.290
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | a3002r_firmware | 4.0.0-b20230531.1404 | Yes |
Hardware | totolink | a3002r | - | No |