CVE-2020-25499: OS Command Injection
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25499?
CVE-2020-25499 is classified as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2020-25499?
To fix CVE-2020-25499, update the affected TOTOLINK A3002RU firmware to a version higher than 2.1.1-b20200911.1756.
Who is affected by CVE-2020-25499?
CVE-2020-25499 affects users of TOTOLINK A3002RU firmware versions from 1.1.1-b20200824.0128 and below.
What can attackers do with CVE-2020-25499?
Attackers exploiting CVE-2020-25499 can execute arbitrary operating system commands remotely on the vulnerable router.
Is there a workaround for CVE-2020-25499?
Currently, the recommended action for CVE-2020-25499 is to update the firmware, as there are no effective workarounds to mitigate the vulnerability.