CVE-2020-25499

TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:a3002r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3002r:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:totolink:a3002ru-v1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3002ru-v1:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:totolink:a3002ru-v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3002ru-v2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:totolink:a702r-v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a702r-v2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:totolink:a702r-v3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a702r-v3:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:totolink:n100re-v3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n100re-v3:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:totolink:n150rt_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n150rt:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:totolink:n200re-v3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n200re-v3:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:totolink:n200re-v4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n200re-v4:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:totolink:n210re_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n210re:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:totolink:n300rh-v3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n300rh-v3:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:totolink:n300rt_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n300rt:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:totolink:n302r_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n302r_plus:-:*:*:*:*:*:*:*

Information

Published : 2020-12-09 13:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-25499

Mitre link : CVE-2020-25499


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-862

Missing Authorization

Advertisement

dedicated server usa

Products Affected

totolink

  • a3002ru-v1_firmware
  • n300rt
  • n210re
  • a3002r_firmware
  • a3002ru-v1
  • n300rh-v3
  • n100re-v3
  • n150rt_firmware
  • n210re_firmware
  • n100re-v3_firmware
  • a702r-v3
  • n200re-v4_firmware
  • a3002ru-v2_firmware
  • n200re-v3
  • a702r-v2_firmware
  • n200re-v4
  • a702r-v3_firmware
  • a702r-v2
  • n300rh-v3_firmware
  • n150rt
  • a3002r
  • n302r_plus
  • a3002ru-v2
  • n302r_plus_firmware
  • n300rt_firmware
  • n200re-v3_firmware