CVE-2020-25499

HIGH EXPLOITED IN THE WILD

TOTOLINK A3002RU-V2 < 2.1.1-b20200911.1756 - Authenticated OS Command Injection via Run Command

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-25499 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.totolink.net/home/index/newsss/id/196.html

Scores

CVSS v3 8.8
EPSS 0.0917
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-01-03
InTheWild.io 2024-05-29
CWE
CWE-78 CWE-862
Status published
Products (13)
totolink/a3002r_firmware < 1.1.1-b20200824.0128
totolink/a3002ru-v1_firmware < 3.4.0-b20201030.1754
totolink/a3002ru-v2_firmware < 2.1.1-b20200911.1756
totolink/a702r-v2_firmware < 1.0.0-b20201028.1743
totolink/a702r-v3_firmware < 1.0.0-b20201103.1713
totolink/n100re-v3_firmware < 3.4.0-b20201030.0926
totolink/n150rt_firmware < 3.4.0-b20201030.1142
totolink/n200re-v3_firmware < 3.4.0-b20201029.1811
totolink/n200re-v4_firmware < 4.0.0-b20200805.1507
totolink/n210re_firmware < 1.0.0-b20201030.2030
... and 3 more
Published Dec 09, 2020
Tracked Since Feb 18, 2026