TOTOLINK N150RT Cross-Site Scripting Vulnerability in Virtual Server Page

Vulnerability

A cross-site scripting vulnerability has been identified in the TOTOLINK N150RT router, specifically in version 3.4.0-B20190525. This issue arises within the Virtual Server Page component, where unknown code can be manipulated to execute malicious scripts. The vulnerability can be exploited remotely, and details of the exploit have been publicly disclosed.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
5.5
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.