CVE Feed

    Dashboard / CVE / CVE-2020-25499

    CVE-2020-25499

    TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.

    Published:Dec 9, 2020
    Last Modified:Nov 21, 2024
    EPS:Dec 9, 2020
    EPSS Score:0.21814
    CVSS Score:8.8

    Affected Products

    Vendor
    Totolink
    Product
    A3002r
    Vendor
    Totolink
    Product
    A3002r Firmware
    Vendor
    Totolink
    Product
    A3002ru-v1
    Vendor
    Totolink
    Product
    A3002ru-v1 Firmware
    Vendor
    Totolink
    Product
    A3002ru-v2
    Vendor
    Totolink
    Product
    A3002ru-v2 Firmware
    Vendor
    Totolink
    Product
    A702r-v2
    Vendor
    Totolink
    Product
    A702r-v2 Firmware
    Vendor
    Totolink
    Product
    A702r-v3
    Vendor
    Totolink
    Product
    A702r-v3 Firmware
    Vendor
    Totolink
    Product
    N100re-v3
    Vendor
    Totolink
    Product
    N100re-v3 Firmware
    Vendor
    Totolink
    Product
    N150rt
    Vendor
    Totolink
    Product
    N150rt Firmware
    Vendor
    Totolink
    Product
    N200re-v3
    Vendor
    Totolink
    Product
    N200re-v3 Firmware
    Vendor
    Totolink
    Product
    N200re-v4
    Vendor
    Totolink
    Product
    N200re-v4 Firmware
    Vendor
    Totolink
    Product
    N210re
    Vendor
    Totolink
    Product
    N210re Firmware
    Vendor
    Totolink
    Product
    N300rh-v3
    Vendor
    Totolink
    Product
    N300rh-v3 Firmware
    Vendor
    Totolink
    Product
    N300rt
    Vendor
    Totolink
    Product
    N300rt Firmware
    Vendor
    Totolink
    Product
    N302r Plus
    Vendor
    Totolink
    Product
    N302r Plus Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High