Total vulnerabilities in the database
Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field.
Software | From | Fixed in |
---|---|---|
totolink / a3002r_firmware | 1.1.1-b20200824 | 1.1.1-b20200824.x |