CVE-2020-25499
HIGH EXPLOITED IN THE WILDTOTOLINK A3002RU-V2 < 2.1.1-b20200911.1756 - Authenticated OS Command Injection via Run Command
Title source: llmExploitation Summary
CVE-2020-25499 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
Description
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.totolink.net/home/index/newsss/id/196.html
Exploit, Third Party Advisory x_refsource_misc
https://github.com/kdoos/Vulnerabilities/blob/main/RCE_TOTOLINK-A3002RU-V2
Scores
CVSS v3
8.8
EPSS
0.0917
EPSS Percentile
92.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-01-03
InTheWild.io
2024-05-29
CWE
CWE-78
CWE-862
Status
published
Products (13)
totolink/a3002r_firmware
< 1.1.1-b20200824.0128
totolink/a3002ru-v1_firmware
< 3.4.0-b20201030.1754
totolink/a3002ru-v2_firmware
< 2.1.1-b20200911.1756
totolink/a702r-v2_firmware
< 1.0.0-b20201028.1743
totolink/a702r-v3_firmware
< 1.0.0-b20201103.1713
totolink/n100re-v3_firmware
< 3.4.0-b20201030.0926
totolink/n150rt_firmware
< 3.4.0-b20201030.1142
totolink/n200re-v3_firmware
< 3.4.0-b20201029.1811
totolink/n200re-v4_firmware
< 4.0.0-b20200805.1507
totolink/n210re_firmware
< 1.0.0-b20201030.2030
... and 3 more
Published
Dec 09, 2020
Tracked Since
Feb 18, 2026