PT-2020-16101 · Totolink · Totolink A3002Ru

Published

2020-12-09

·

Updated

2025-01-23

·

CVE-2020-25499

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A3002RU version 2.0.0 B20190814.1034
Description The issue allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
Recommendations For TOTOLINK A3002RU version 2.0.0 B20190814.1034, consider disabling the 'Run Command' functionality until a patch is available to prevent the execution of arbitrary OS commands. Restrict access to the router to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-25499

Affected Products

Totolink A3002Ru