CVE-2025-3249

A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

07 Apr 2025, 14:18

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad clasificada como crítica en TOTOLINK A6000R 1.0.1-B20201211.2000. Esta vulnerabilidad afecta la función apcli_cancel_wps del archivo /usr/lib/lua/luci/controller/mtkwifi.lua. La manipulación provoca la inyección de comandos. El ataque puede ejecutarse remotamente. Se ha hecho público el exploit y puede que sea utilizado.

04 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-04 14:15

Updated : 2025-04-07 14:18


NVD link : CVE-2025-3249

Mitre link : CVE-2025-3249

CVE.ORG link : CVE-2025-3249


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')