TOTOLINK N300RT
cpe:2.3:h:totolink:n300rt:*:*:*:*:*:*:*, +1 more
- < V3.4.0-B20250430
A command injection vulnerability has been identified in the TOTOLINK N300RT wireless router, affecting firmware versions prior to V3.4.0-B20250430. This vulnerability arises in the Boa web server's formWsc handling, where an unauthenticated attacker can execute arbitrary commands by sending specially crafted requests that include the targetAPSsid parameter.
Exploitation of this vulnerability allows for arbitrary command execution on the router.
Users can upgrade to TOTOLINK N300RT firmware version V3.4.0-B20250430 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.