CVE-2020-25499

TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
totolinka3002r_firmware
𝑥
< 1.1.1-b20200824.0128
totolinka3002ru-v1_firmware
𝑥
< 3.4.0-b20201030.1754
totolinka3002ru-v2_firmware
𝑥
< 2.1.1-b20200911.1756
totolinka702r-v2_firmware
𝑥
< 1.0.0-b20201028.1743
totolinka702r-v3_firmware
𝑥
< 1.0.0-b20201103.1713
totolinkn100re-v3_firmware
𝑥
< 3.4.0-b20201030.0926
totolinkn150rt_firmware
𝑥
< 3.4.0-b20201030.1142
totolinkn200re-v3_firmware
𝑥
< 3.4.0-b20201029.1811
totolinkn200re-v4_firmware
𝑥
< 4.0.0-b20200805.1507
totolinkn210re_firmware
𝑥
< 1.0.0-b20201030.2030
totolinkn300rh-v3_firmware
𝑥
< 3.2.4-b20201029.1838
totolinkn300rt_firmware
𝑥
< 3.4.0-b20201026.2033
totolinkn302r_plus_firmware
𝑥
< 3.4.0-b20201028.2224
𝑥
= Vulnerable software versions