Vulnerability Description
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | A3002R Firmware | < 1.1.1-b20200824.0128 |
| Totolink | A3002R | - |
| Totolink | A3002Ru-V1 Firmware | < 3.4.0-b20201030.1754 |
| Totolink | A3002Ru-V1 | - |
| Totolink | A3002Ru-V2 Firmware | < 2.1.1-b20200911.1756 |
| Totolink | A3002Ru-V2 | - |
| Totolink | A702R-V2 Firmware | < 1.0.0-b20201028.1743 |
| Totolink | A702R-V2 | - |
| Totolink | A702R-V3 Firmware | < 1.0.0-b20201103.1713 |
| Totolink | A702R-V3 | - |
| Totolink | N100Re-V3 Firmware | < 3.4.0-b20201030.0926 |
| Totolink | N100Re-V3 | - |
| Totolink | N150Rt Firmware | < 3.4.0-b20201030.1142 |
| Totolink | N150Rt | - |
| Totolink | N200Re-V3 Firmware | < 3.4.0-b20201029.1811 |
| Totolink | N200Re-V3 | - |
| Totolink | N200Re-V4 Firmware | < 4.0.0-b20200805.1507 |
| Totolink | N200Re-V4 | - |
| Totolink | N210Re Firmware | < 1.0.0-b20201030.2030 |
| Totolink | N210Re | - |
Related Weaknesses (CWE)
References
- https://github.com/kdoos/Vulnerabilities/blob/main/RCE_TOTOLINK-A3002RU-V2ExploitThird Party Advisory
- https://www.totolink.net/home/index/newsss/id/196.htmlPatchVendor Advisory
- https://github.com/kdoos/Vulnerabilities/blob/main/RCE_TOTOLINK-A3002RU-V2ExploitThird Party Advisory
- https://www.totolink.net/home/index/newsss/id/196.htmlPatchVendor Advisory
FAQ
What is CVE-2020-25499?
CVE-2020-25499 is a vulnerability with a CVSS score of 8.8 (HIGH). TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
How severe is CVE-2020-25499?
CVE-2020-25499 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25499?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink A3002R Firmware, Totolink A3002R, Totolink A3002Ru-V1 Firmware, Totolink A3002Ru-V1, Totolink A3002Ru-V2 Firmware.