VYPR
Critical severity9.8NVD Advisory· Published Feb 24, 2022· Updated Jun 17, 2026

CVE-2022-25075

CVE-2022-25075

Description

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

Affected products

3
  • Totolink/A3000RUllm-fuzzy2 versions
    = V5.9c.2280_B20180512+ 1 more
    • (no CPE)range: = V5.9c.2280_B20180512
    • (no CPE)
  • cpe:2.3:o:totolink:a3000ru_firmware:v5.9c.2280_b20180512:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.