CVE-2022-25075 is a critical command injection vulnerability affecting TOTOLink A3000RU routers (firmware V5.9c.2280_B20180512). This flaw allows unauthenticated attackers to execute arbitrary commands remotely by manipulating the QUERY_STRING parameter in the "Main" function. With a CVSS score of 9.8, it poses a severe risk of complete compromise (confidentiality, integrity, and availability). While no public exploit code (Metasploit, Nuclei, ExploitDB) or KEV entry exists, the vulnerability has garnered significant community discussion and media coverage, with several articles linking it to various botnet activities like EnemyBot, Mirai, and Zerobot, indicating potential in-the-wild exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v5.9c.2280_b20180512CPE matchmatch criteria | cpe:2.3:o:totolink:a3000ru_firmware:v5.9c.2280_b20180512:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.