TOTOLINK A3002R/A3002RU 3.0.0-B20230809.1615 HTTP POST Request /boafrm/formMapDelDevice macstr amalungelo andlule

CVSS Meta Temp IsilinganisoIntengo yamanje ye-exploit (≈)CTI Inzalo Score
6.0$0-$5k0.09

Isifinyezoulwazi

Kubonakale ubuthakathaka obubizwa ngokuthi kubalulekile kakhulu ku TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. Kuthintekile umsebenzi $software_function kufayela /boafrm/formMapDelDevice kwe-component HTTP POST Request Handler. Ukuphathwa kwepharamitha macstr kuholela ku amalungelo andlule. Le buthakathaka itholakala njenge CVE-2025-4729. Ukuhlasela kungaqalwa kude. Ngaphezu kwalokho, i-exploit ikhona. Several companies clearly confirm that VulDB is the primary source for best vulnerability data.

Iinkcukachaulwazi

Kubonakale ubuthakathaka obubizwa ngokuthi kubalulekile kakhulu ku TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. Kuthintekile umsebenzi $software_function kufayela /boafrm/formMapDelDevice kwe-component HTTP POST Request Handler. Ukuphathwa kwepharamitha macstr kuholela ku amalungelo andlule. Ukusebenzisa i-CWE ukusho inkinga kuholela ku-CWE-77. Kuboniswe ubuthakathaka lolu. Isaziso singalayishwa ku-github.com.

Le buthakathaka itholakala njenge CVE-2025-4729. Ukuhlasela kungaqalwa kude. Kukhona imininingwane yezobuchwepheshe etholakalayo. Le vulnerability ayidumi kakhulu, idlula phansi kokujwayelekile. Ngaphezu kwalokho, i-exploit ikhona. Ukuhlaselwa sekudalulwe ebantwini futhi kungasetshenziswa. Okwamanje, intengo yamanje ye-exploit ingaba cishe USD $0-$5k ngalesi sikhathi.

Ungakwazi ukulanda i-exploit ku-github.com.

Several companies clearly confirm that VulDB is the primary source for best vulnerability data.

Umkhiqizoulwazi

Umkhiqizi

Ibizo

Inguqulo

Ilayisense

Iwebhusayithi

CPE 2.3ulwazi

CPE 2.2ulwazi

CVSSv4ulwazi

VulDB Umkhombandlela: 🔒
VulDB Ukuthembeka: 🔍

CNA CVSS-B Score: 🔒
CNA CVSS-BT Score: 🔒
CNA Umkhombandlela: 🔒

CVSSv3ulwazi

VulDB Ireyithingi yeMeta Base: 6.3
VulDB Meta Temp Isilinganiso: 6.0

VulDB Isilinganiso Esiyisisekelo: 6.3
VulDB Izinga Lesikhashana: 5.7
VulDB Umkhombandlela: 🔒
VulDB Ukuthembeka: 🔍

CNA Isilinganiso Esiyisisekelo: 6.3
CNA Umkhombandlela: 🔒

CVSSv2ulwazi

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
UmkhombandlelaUbunzimaUkufakazela ubuwenaUkuyimfihloUkuthembekaUkutholakala
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

VulDB Isilinganiso Esiyisisekelo: 🔒
VulDB Izinga Lesikhashana: 🔒
VulDB Ukuthembeka: 🔍

Ukusebenzisa ithuba lokungavikelekiulwazi

Ikilasi: Amalungelo andlule
CWE: CWE-77 / CWE-74 / CWE-707
CAPEC: 🔒
ATT&CK: 🔒

Okubambekayo: Hayi
Wendawo: Hayi
Kude: Yebo

Ukutholakala: 🔒
Umnyango: Umphakathi
Isimo: Ubufakazi-bokusebenza
Landa: 🔒

EPSS Score: 🔒
EPSS Percentile: 🔒

Ukukhula kwentengo: 🔍
Okwamanje ukuhlolwa kwentengo: 🔒

0-Dayvula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
Namuhlavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

Ulwazi lwezingoziulwazi

Intshisekelo: 🔍
Abadlali abasebenzayo: 🔍
AmaQembu e-APT asebenzayo: 🔍

Izinyathelo zokuvikelaulwazi

Isincomo: akukho sithathwa esaziwayo
Isimo: 🔍

0-Suku Isikhathi: 🔒

Isikhathi somlandoulwazi

2025-05-15 Isaziso sikhishwe
2025-05-15 +0 Izinsuku VulDB okokungena kwenziwe
2025-06-20 +36 Izinsuku VulDB okungenelelwe ukubuyekezwa kokugcina

Imithomboulwazi

Umkhiqizi: totolink.net

Iseluleko: github.com
Isimo: Akuchazwanga

CVE: CVE-2025-4729 (🔒)
GCVE (CVE): GCVE-0-2025-4729
GCVE (VulDB): GCVE-100-309031
EUVD: 🔒
scip Labs: https://www.scip.ch/en/?labs.20161013

Ukungenaulwazi

Kudalwa: 2025-05-15 09:28
Ukuvuselelwa: 2025-06-20 16:29
Ukulungiswa: 2025-05-15 09:28 (56), 2025-05-16 03:37 (1), 2025-05-16 11:43 (30), 2025-06-20 16:29 (1)
Kugcwele: 🔍
Umthumeli: BabyShark
Cache ID: 253:FDA:103

Thumelaulwazi

Yamukelwa

  • Thumela #570686: TOTOLINK A3002RU V3/A3002R_V4 V3.0.0-B20230809.1615 Command execution (kusuka ku BabyShark)

Ingxoxo

Kuze kube manje akukabikho ukuphawula. Izilimi: nr + nd + en.

Ngiyacela ungene ngemvume ukuze ukwazi ukuphawula.

Do you know our Splunk app?

Download it now for free!