TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.
| Software | From | Fixed in |
|---|---|---|
| totolink / a3002r_firmware | 4.0.0-b20230531.1404 | 4.0.0-b20230531.1404.x |