TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
https://github.com/kuznyJan1972/CVE-2022-25075-rce-POC
https://github.com/kuznyJan1972/CVE-2022-25075-RCE
https://github.com/EPhaha/IOT_vuln/blob/main/TOTOLink/A3000RU/README.md