A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Thu, 15 May 2025 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
Title | TOTOLINK A3002R/A3002RU HTTP POST Request formMapDelDevice command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-05-15T23:31:06.917Z
Updated: 2025-05-15T23:31:06.917Z
Reserved: 2025-05-15T07:23:06.748Z
Link: CVE-2025-4729

No data.

Status : Received
Published: 2025-05-16T00:15:19.793
Modified: 2025-05-16T00:15:19.793
Link: CVE-2025-4729

No data.