CVE-2025-34319

TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vulnerability in the Boa formWsc handling functionality. An unauthenticated attacker can send specially crafted requests to trigger command execution via the targetAPSsid request parameter.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Dec 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-03 17:15

Updated : 2025-12-03 17:15


NVD link : CVE-2025-34319

Mitre link : CVE-2025-34319

CVE.ORG link : CVE-2025-34319


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')