TOTOLINK A3002RU
cpe:2.3:h:totolink:a3002ru:*:*:*:*:*:*:*, +1 more
- 2.1.1-B20230720.1011
A cross-site scripting (XSS) vulnerability has been identified in the TOTOLINK A3002RU router, specifically in the firmware version 2.1.1-B20230720.1011. The issue arises within the IP Port Filtering component of the Firewall page, where user input in the Comment field is not properly sanitized. This flaw allows for the injection of malicious scripts that are executed in the context of the user viewing the page.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed when the affected page is viewed by users.
To reproduce this vulnerability, navigate to the IP Port Filtering section under the Firewall page. Enter a script payload, such as an SVG image with an onload event, into the Comment input box. After submitting the form, the injected script will execute when the page is accessed, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.