ZeroHour

CVE-2020-25499

PoC
CVSS 3.1
8.8 high
EPSS
4%p91
Published
()
Modified
Description

TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.

Vendors
totolink
Products
a3002r firmware, a3002ru-v1 firmware, a3002ru-v2 firmware, a702r-v2 firmware, a702r-v3 firmware, n100re-v3 firmware, n150rt firmware, n200re-v3 firmware, n200re-v4 firmware, n210re firmware, n300rh-v3 firmware, n300rt firmware
Weakness
CWE-78, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news