{"advisories":[{"id":"EUVD-2025-12424","source":"euvd","title":"A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-12424"}],"cve":"CVE-2025-3987","epss":{"score":0.10488},"mitre":{"cpes":[],"created":"2025-04-27T21:31:06.521000+00:00","description":"A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P"},"cvssV3_0":{"score":6.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{"score":5.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2025/3xxx/CVE-2025-3987.json","references":["https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/N150RT/RCE_formWsc","https://vuldb.com/?ctiid.306323","https://vuldb.com/?id.306323","https://vuldb.com/?submit.557938","https://www.totolink.net/"],"title":"TOTOLINK N150RT formWsc command injection","updated":"2025-04-28T17:28:10.520000+00:00","vendors":[],"weaknesses":["CWE-74","CWE-77"]},"nvd":{"cpes":["cpe:2.3:h:totolink:n150rt:2.0:*:*:*:*:*:*:*","cpe:2.3:o:totolink:n150rt_firmware:3.4.0-b20190525:*:*:*:*:*:*:*"],"created":"2025-04-27T22:15:14.863000+00:00","description":"A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{"score":5.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2025/CVE-2025-3987.json","references":["https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/N150RT/RCE_formWsc","https://vuldb.com/?ctiid.306323","https://vuldb.com/?id.306323","https://vuldb.com/?submit.557938","https://www.totolink.net/"],"title":null,"updated":"2026-06-17T09:21:03.990000+00:00","vendors":["totolink","totolink$PRODUCT$n150rt","totolink$PRODUCT$n150rt_firmware"],"weaknesses":["CWE-74","CWE-77"]},"opencve":{"changes":[{"created":"2025-04-27T21:45:00+00:00","data":[{"details":{"new":"A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","old":null},"type":"description"},{"details":{"new":"TOTOLINK N150RT formWsc command injection","old":null},"type":"title"},{"details":{"added":["CWE-74","CWE-77"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/N150RT/RCE_formWsc","https://vuldb.com/?ctiid.306323","https://vuldb.com/?id.306323","https://vuldb.com/?submit.557938","https://www.totolink.net/"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV2_0":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P"},"cvssV3_0":{"score":6.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{"score":5.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"320577a8-ca12-4003-8873-62575520d5e7"},{"created":"2025-04-28T18:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"eea8e2dd-b1e9-4f33-b38a-926d8d76d1bb"},{"created":"2025-05-07T19:00:00+00:00","data":[{"details":["totolink","totolink$PRODUCT$n150rt","totolink$PRODUCT$n150rt_firmware"],"type":"first_time"},{"details":{"added":["cpe:2.3:h:totolink:n150rt:2.0:*:*:*:*:*:*:*","cpe:2.3:o:totolink:n150rt_firmware:3.4.0-b20190525:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["totolink","totolink$PRODUCT$n150rt","totolink$PRODUCT$n150rt_firmware"],"removed":[]},"type":"vendors"}],"id":"df15621c-4ffd-470a-841c-b65fb6e52c37"},{"created":"2025-07-13T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.02839},"old":{"score":0.03153}}}},"type":"metrics"}],"id":"b752c1f7-2793-4c3d-9595-8cab5ca90bd6"}],"cpes":{"data":["cpe:2.3:h:totolink:n150rt:2.0:*:*:*:*:*:*:*","cpe:2.3:o:totolink:n150rt_firmware:3.4.0-b20190525:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2025-04-27T21:31:06.521000+00:00","provider":"mitre"},"description":{"data":"A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P"},"provider":"mitre"},"cvssV3_0":{"data":{"score":6.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"provider":"mitre"},"cvssV3_1":{"data":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"provider":"mitre"},"cvssV4_0":{"data":{"score":5.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{"score":0.10488},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/fizz-is-on-the-way/Iot_vuls/tree/main/N150RT/RCE_formWsc","https://vuldb.com/?ctiid.306323","https://vuldb.com/?id.306323","https://vuldb.com/?submit.557938","https://www.totolink.net/"],"providers":["mitre","nvd"]},"title":{"data":"TOTOLINK N150RT formWsc command injection","provider":"mitre"},"updated":{"data":"2025-05-07T18:36:05.907000+00:00","provider":"nvd"},"vendors":{"data":["totolink","totolink$PRODUCT$n150rt","totolink$PRODUCT$n150rt_firmware"],"providers":["nvd"]},"weaknesses":{"data":["CWE-74","CWE-77"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-04-27T21:31:06.521000+00:00","description":"A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"TOTOLINK N150RT formWsc command injection","updated":"2025-04-28T17:27:55.313000+00:00","vendors":[],"vulnrichment_repo_path":"2025/3xxx/CVE-2025-3987.json","weaknesses":[]}}