TOTOLINK X2000R URL Filtering Page formFilter cross site scripting

CVE Details

Basic Information

Title TOTOLINK X2000R URL Filtering Page formFilter cross site scripting
Type cve
Published 2025-06-03T18:00:18.786Z
Last Seen

Product Information

Vendor TOTOLINK
Product X2000R
Version 1.0.0-B20230726.1108

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description This vulnerability is a cross-site scripting (XSS) issue in the URL Filtering Page of the TOTOLINK X2000R router. It allows remote attackers to inject malicious scripts via the URL Address argument in the formFilter component. The flaw could enable unauthorized actions or data exposure.
AI Severity Medium
Vendor TOTOLINK
Product TOTOLINK X2000R
Affected Version 1.0.0-B20230726.1108

Additional Information

CVE List
CWE List CWE-79, CWE-94
Bulletin Family
Source Data TOTOLINK X2000R 1.0.0-B20230726.1108

Source Information

Source Data TOTOLINK X2000R 1.0.0-B20230726.1108
Source Link

Description

A vulnerability, which was classified as problematic, was found in TOTOLINK X2000R 1.0.0-B20230726.1108. This affects an unknown part of the file /boafrm/formFilter of the component URL Filtering Page. The manipulation of the argument URL Address leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Score Summary

Base Score: 4.8 (MEDIUM)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.