Showing 3 vulnerabilities on this page for n150rt_firmware

Signals CISA KEV Ransomware Nuclei
totolink vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

TOTOLINK N150RT formWsc command injection

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CWE-74CWE-77Apr 27, 2025
CVSS5.3v4.0EPSS9.71%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

totolink a3002ru Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formSysCmd component.

CWE-78Nov 27, 20241 related artifact
CVSS6.8v3.1EPSS3.79%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

totolink a3002ru Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.

CWE-78Jan 27, 20201 related artifact
CVSS8.8v3.1EPSS25.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX