Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28714 | A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the argument targetAPSsid leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 02 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink
Totolink n150rt Totolink n150rt Firmware |
|
| CPEs | cpe:2.3:h:totolink:n150rt:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:n150rt_firmware:3.4.0-b20190525:*:*:*:*:*:*:* |
|
| Vendors & Products |
Totolink
Totolink n150rt Totolink n150rt Firmware |
Fri, 20 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Jun 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the argument targetAPSsid leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | TOTOLINK N150RT formWSC os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-06-20T19:28:36.983Z
Reserved: 2025-06-19T07:47:47.419Z
Link: CVE-2025-6299
Updated: 2025-06-20T19:28:29.363Z
Status : Analyzed
Published: 2025-06-20T03:15:28.060
Modified: 2025-07-02T18:53:41.497
Link: CVE-2025-6299
No data.
OpenCVE Enrichment
Updated: 2025-06-23T08:20:14Z
EUVD