← Back to browse
·
API
CVE-2025-25579
Severity
CRITICAL
CVSS
9.8
EPSS
0.10079
Risk score
42.73
CISA KEV
No
PoC
No
Published
2025-03-28
Modified
2025-03-31
First seen
2026-08-07
Aliases
EUVD-2025-8669, GHSA-GC26-WQWP-QR8C
Products
n/a:n/a n/a
Sources
euvd
EUVD-2025-8669
Description
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
References
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-8669
https://github.com/regainer27/totolink_A3002R_remote_command_exec
https://gist.github.com/regainer27/0abf6f56eae3fa2826d2551e22c2ace3