OS Command Injection Vulnerability in TOTOLINK N300RT Wireless Router
CVE-2025-34319
9.3CRITICAL
What is CVE-2025-34319?
The TOTOLINK N300RT wireless router is susceptible to an OS command injection vulnerability stemming from improper handling of the Boa formWsc functionality. This allows unauthorized attackers to craft specific requests that can execute arbitrary commands on the device through the targetAPSSID request parameter, potentially compromising the device's integrity and exposing sensitive information.
Affected Version(s)
N300RT 0
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
YuChieh Kuo
ShiYi Xie
Zhen-Gao Liu
