ID

VAR-202503-4138


CVE

CVE-2025-25579


TITLE

TOTOLINK  of  A3002R  in the firmware  OS  Command injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2025-003150

DESCRIPTION

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr. TOTOLINK of A3002R The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TOTOLINK A3002R is a wireless router from China's TOTOLINK Electronics. TOTOLINK A3002R has a command injection vulnerability, which is caused by the failure of bandstr to properly filter special characters and commands in constructing commands. Attackers can use this vulnerability to execute arbitrary commands

Trust: 2.16

sources: NVD: CVE-2025-25579 // JVNDB: JVNDB-2025-003150 // CNVD: CNVD-2025-12088

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-12088

AFFECTED PRODUCTS

vendor:totolinkmodel:a3002rscope:eqversion:4.0.0-b20230531.1404

Trust: 1.0

vendor:totolinkmodel:a3002rscope:eqversion:a3002r firmware 4.0.0-b20230531.1404

Trust: 0.8

vendor:totolinkmodel:a3002rscope:eqversion: -

Trust: 0.8

vendor:totolinkmodel:a3002rscope: - version: -

Trust: 0.8

vendor:totolinkmodel:a3002r v4.0.0-b20230531.1404scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-12088 // JVNDB: JVNDB-2025-003150 // NVD: CVE-2025-25579

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-25579
value: CRITICAL

Trust: 1.0

OTHER: JVNDB-2025-003150
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2025-12088
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-12088
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-25579
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-003150
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-12088 // JVNDB: JVNDB-2025-003150 // NVD: CVE-2025-25579

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.0

problemtype:OS Command injection (CWE-78) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-003150 // NVD: CVE-2025-25579

EXTERNAL IDS

db:NVDid:CVE-2025-25579

Trust: 3.2

db:JVNDBid:JVNDB-2025-003150

Trust: 0.8

db:CNVDid:CNVD-2025-12088

Trust: 0.6

sources: CNVD: CNVD-2025-12088 // JVNDB: JVNDB-2025-003150 // NVD: CVE-2025-25579

REFERENCES

url:https://gist.github.com/regainer27/0abf6f56eae3fa2826d2551e22c2ace3

Trust: 2.4

url:https://github.com/regainer27/totolink_a3002r_remote_command_exec

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2025-25579

Trust: 0.8

sources: CNVD: CNVD-2025-12088 // JVNDB: JVNDB-2025-003150 // NVD: CVE-2025-25579

SOURCES

db:CNVDid:CNVD-2025-12088
db:JVNDBid:JVNDB-2025-003150
db:NVDid:CVE-2025-25579

LAST UPDATE DATE

2025-06-15T23:39:20.234000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-12088date:2025-06-11T00:00:00
db:JVNDBid:JVNDB-2025-003150date:2025-04-10T04:40:00
db:NVDid:CVE-2025-25579date:2025-04-07T14:23:36.660

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-12088date:2025-06-10T00:00:00
db:JVNDBid:JVNDB-2025-003150date:2025-04-10T00:00:00
db:NVDid:CVE-2025-25579date:2025-03-28T22:15:17.597