TOTOLINK A3002RU
cpe:2.3:h:totolink:a3002ru:*:*:*:*:*:*:*, +1 more
- A3002RU V2_Firmware V2.1.1-B20230720.1011
A cross-site scripting (XSS) vulnerability has been identified in the TOTOLINK A3002RU router, specifically in the firmware version 2.1.1-B20230720.1011. The issue arises within the Virtual Server component of the NAT Mapping page, where the 'Service Type' input is not properly sanitized. This flaw allows for the injection of malicious scripts that could be executed in the context of the user's browser.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed when the affected page is viewed by users.
To reproduce this vulnerability, navigate to the NAT Mapping page and select the Virtual Server option. In the Service Type input box, enter a script payload. After sending the request, refresh the Virtual Server page to execute the injected script. The JavaScript will run, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.