CVE-2025-5508: TOTOLINK A3002RU IP Port Filtering Page cross site scripting
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IP Port Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5508?
CVE-2025-5508 has been rated as problematic.
What functionality is affected by CVE-2025-5508?
CVE-2025-5508 affects the IP Port Filtering Page component of the TOTOLINK A3002RU.
What type of vulnerability is CVE-2025-5508?
CVE-2025-5508 is a cross-site scripting (XSS) vulnerability.
How can CVE-2025-5508 be exploited?
CVE-2025-5508 can be exploited by manipulating the Comment argument in the affected component.
How do I fix CVE-2025-5508?
To fix CVE-2025-5508, apply the latest security updates or patches from TOTOLINK for the A3002RU.