CVE detail
CVE-2025-4852
A vulnerability, which was classified as problematic, has been found in TOTOLINK A3002R 2.1.1-B20230720.1011. This issue affects some unknown processing of the component VPN Page. The manipulation of the argument Comment leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.totolink.net/www.totolink.net
No excerpt available.
Productwww.totolink.netMay 18, 2025, 4:15 AM - https://vuldb.com/?submit.575099vuldb.com
No excerpt available.
Exploitvuldb.comMay 18, 2025, 4:15 AM - https://vuldb.com/?id.309323vuldb.com
No excerpt available.
Exploitvuldb.comMay 18, 2025, 4:15 AM - https://vuldb.com/?ctiid.309323vuldb.com
No excerpt available.
Exploitvuldb.comMay 18, 2025, 4:15 AM No excerpt available.
Exploitgithub.comMay 18, 2025, 4:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- fizz-is-on-the-way/Iot_vulsHigh confidencegithubNVD Exploit reference0 starsDiscovered Aug 8, 2026, 6:20 AM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-54907CVSS 8.8 · High
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
- CVE-2021-34228CVSS 6.1 · Medium
Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the…
- CVE-2021-34223CVSS 6.1 · Medium
Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL…
- CVE-2021-34220CVSS 6.1 · Medium
Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "U…
- CVE-2021-34215CVSS 6.1 · Medium
Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Serv…
- CVE-2021-34207CVSS 6.1 · Medium
Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain N…