TOTOLINK X2000R Cross-Site Scripting Vulnerability in Virtual Server Page

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the TOTOLINK X2000R router, specifically in the firmware version 1.0.0-B20230726.1108. The issue arises in the Virtual Server component of the NAT Mapping page, where the 'Service Type' input is not properly validated. This flaw allows for the injection of malicious scripts that could be executed when the page is viewed by other users.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the Virtual Server page.

Reproduction

To reproduce this vulnerability, navigate to the NAT Mapping page and select the Virtual Server option. In the 'Service Type' box, enter a script payload. Once the request is sent, refresh the Virtual Server page to execute the injected script. The JavaScript will run, demonstrating the cross-site scripting vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.7
exploitability
6.0
remediation
0.0
relevance
0.1
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.