CVE-2022-25077 is a critical command injection vulnerability affecting TOTOLink A3100R V4.1.2cu.5050_B20200504 firmware, specifically within the "Main" function via the QUERY_STRING parameter. This flaw carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild or public exploit code on platforms like Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media attention, including its mention in relation to Mirai DDoS malware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.2cu.5050_b20200504CPE matchmatch criteria | cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5050_b20200504:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.