CVE-2022-25075Active Exploitation(totolink / a3000ru)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch totolink a3000ru systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • a3000ru
  • a3000ru_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
a3000rua3000ru_firmware

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-05: 1PoC Mentioned / Linked · 2026-02-05: 1Exploit Tool / Code · 2026-02-05: 1Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-05: 102-05
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2022-25075 : TOTOLINK A3000RU ROUTER UNAUTHENTICATED RCE 🚨 A critical unauthenticated OS command injection vulnerability has been identified in the TOTOLink A3000RU router, allowing remote attackers to execute arbitrary commands as root via the web-based management interface. Risk Severity: - Critical — Active exploitation confirmed - Public proof-of-concept available - Actively weaponized by Mirai and IoT botnet variants Impact: - Unauthenticated remote code execution as root - Complete router takeover and firmware manipulation - Network traffic interception, modification, and credential theft - Lateral movement into connected enterprise and home devices - Botnet enrollment for DDoS, scanning, or cryptomining campaigns Root Cause: - CWE-78 (OS Command Injection). The router’s web server improperly handles the `QUERY_STRING` environment variable, passing attacker-controlled input directly to `system()` without sanitization or escaping. Attackers can: - Send crafted HTTP requests to the router’s management interface - Inject shell metacharacters into the query string - Execute arbitrary OS commands with root privileges - Install persistent malware or backdoored firmware - Monitor, redirect, or tamper with all network traffic Are You Affected? - Vulnerable: TOTOLink A3000RU firmware V5.9c.2280_B20180512 - Exposure: Internet-facing management interfaces - Threat Status: Actively exploited in the wild - Fix Status: No publicly documented patched firmware Immediate Action Required: - Patch / Replace: Contact TOTOLink for updated firmware immediately — if unavailable, replace the device - Disable: Turn off WAN-side web management access entirely - Restrict: Allow administrative access only from LAN or via secure VPN - Block: Enforce firewall rules denying inbound HTTP/HTTPS access to the router from the internet Detection & Monitoring: - Review router logs for query strings containing `; | & $( ) `` - Watch for unexpected outbound connections, config changes, or CPU spikes - Enable syslog forwarding to centralized monitoring where supported Incident Response: If compromise is suspected: - Immediately disconnect the router from all networks - Factory reset with verified clean firmware or decommission the device - Assess downstream systems for credential theft or lateral movement - Rotate credentials for any systems behind the router Why This Matters: SOHO routers are prime botnet targets. An exposed management interface here equals instant root compromise and total network visibility. Legacy firmware plus active exploitation makes this a drop-everything fix. Secure the edge. 🛡️ #ostorlabCVE

    Post summary

    The post announces that CVE‑2022‑25075 in TOTOLINK A3000RU routers is actively exploited in the wild, with a public PoC and Mirai botnet weaponization, and urges immediate patching and disabling of WAN‑side management.

    0001193
    582 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtotolinka3000ru---
OStotolinka3000ru_firmwarev5.9c.2280_b20180512--

Explore more