OS Command Injection Vulnerability in TOTOLINK N300RT Wireless Router
CVE-2025-34319

9.3CRITICAL

Key Information:

Vendor

Totolink

Status
Vendor
CVE Published:
3 December 2025

What is CVE-2025-34319?

The TOTOLINK N300RT wireless router is susceptible to an OS command injection vulnerability stemming from improper handling of the Boa formWsc functionality. This allows unauthorized attackers to craft specific requests that can execute arbitrary commands on the device through the targetAPSSID request parameter, potentially compromising the device's integrity and exposing sensitive information.

Affected Version(s)

N300RT 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

YuChieh Kuo
ShiYi Xie
Zhen-Gao Liu
.
CVE-2025-34319 : OS Command Injection Vulnerability in TOTOLINK N300RT Wireless Router