High severity8.8NVD Advisory· Published Dec 9, 2020· Updated Jun 17, 2026
CVE-2020-25499
CVE-2020-25499
Description
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- TOTOLINK/A3002RUdescription
- cpe:2.3:o:totolink:a3002r_firmware:*:*:*:*:*:*:*:*Range: <1.1.1-b20200824.0128
- cpe:2.3:o:totolink:a3002ru-v1_firmware:*:*:*:*:*:*:*:*Range: <3.4.0-b20201030.1754
- cpe:2.3:o:totolink:a3002ru-v2_firmware:*:*:*:*:*:*:*:*Range: <2.1.1-b20200911.1756
- cpe:2.3:o:totolink:a702r-v2_firmware:*:*:*:*:*:*:*:*Range: <1.0.0-b20201028.1743
- cpe:2.3:o:totolink:a702r-v3_firmware:*:*:*:*:*:*:*:*Range: <1.0.0-b20201103.1713
- cpe:2.3:o:totolink:n100re-v3_firmware:*:*:*:*:*:*:*:*Range: <3.4.0-b20201030.0926
- cpe:2.3:o:totolink:n150rt_firmware:*:*:*:*:*:*:*:*Range: <3.4.0-b20201030.1142
- cpe:2.3:o:totolink:n200re-v3_firmware:*:*:*:*:*:*:*:*Range: <3.4.0-b20201029.1811
- cpe:2.3:o:totolink:n200re-v4_firmware:*:*:*:*:*:*:*:*Range: <4.0.0-b20200805.1507
- cpe:2.3:o:totolink:n210re_firmware:*:*:*:*:*:*:*:*Range: <1.0.0-b20201030.2030
- cpe:2.3:o:totolink:n300rh-v3_firmware:*:*:*:*:*:*:*:*Range: <3.2.4-b20201029.1838
- cpe:2.3:o:totolink:n300rt_firmware:*:*:*:*:*:*:*:*Range: <3.4.0-b20201026.2033
- cpe:2.3:o:totolink:n302r_plus_firmware:*:*:*:*:*:*:*:*Range: <3.4.0-b20201028.2224
Patches
Vulnerability mechanics
References
2- www.totolink.net/home/index/newsss/id/196.htmlnvdPatchVendor Advisory
- github.com/kdoos/Vulnerabilities/blob/main/RCE_TOTOLINK-A3002RU-V2nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.