Total vulnerabilities in the database
Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field.
Software | From | Fixed in |
---|---|---|
totolink / a3002r_firmware | 1.1.1-b20200824 | 1.1.1-b20200824.x |