cbcvebase.
CVE-2020-25499
published 2020-12-09

CVE-2020-25499: TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to…

PriorityP278high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
4.23%
89.9th percentile
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.

Affected

13 ranges
VendorProductVersion rangeFixed in
totolinka3002r_firmware< 1.1.1-b20200824.01281.1.1-b20200824.0128
totolinka3002ru-v1_firmware< 3.4.0-b20201030.17543.4.0-b20201030.1754
totolinka3002ru-v2_firmware< 2.1.1-b20200911.17562.1.1-b20200911.1756
totolinka702r-v2_firmware< 1.0.0-b20201028.17431.0.0-b20201028.1743
totolinka702r-v3_firmware< 1.0.0-b20201103.17131.0.0-b20201103.1713
totolinkn100re-v3_firmware< 3.4.0-b20201030.09263.4.0-b20201030.0926
totolinkn150rt_firmware< 3.4.0-b20201030.11423.4.0-b20201030.1142
totolinkn200re-v3_firmware< 3.4.0-b20201029.18113.4.0-b20201029.1811
totolinkn200re-v4_firmware< 4.0.0-b20200805.15074.0.0-b20200805.1507
totolinkn210re_firmware< 1.0.0-b20201030.20301.0.0-b20201030.2030
totolinkn300rh-v3_firmware< 3.2.4-b20201029.18383.2.4-b20201029.1838
totolinkn300rt_firmware< 3.4.0-b20201026.20333.4.0-b20201026.2033
totolinkn302r_plus_firmware< 3.4.0-b20201028.22243.4.0-b20201028.2224

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.