TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
References
| Link | Resource |
|---|---|
| https://gist.github.com/regainer27/0abf6f56eae3fa2826d2551e22c2ace3 | Exploit Third Party Advisory |
| https://github.com/regainer27/totolink_A3002R_remote_command_exec | Exploit Third Party Advisory |
| https://github.com/regainer27/totolink_A3002R_remote_command_exec | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-03-28 22:15
Updated : 2025-04-07 14:23
NVD link : CVE-2025-25579
Mitre link : CVE-2025-25579
CVE.ORG link : CVE-2025-25579
JSON object : View
Products Affected
totolink
- a3002r_firmware
- a3002r
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
