Command Execution Vulnerability in TOTOLINK A950RG by TOTOLINK
CVE-2025-45798
9.8CRITICAL
What is CVE-2025-45798?
A command execution vulnerability is present in the TOTOLINK A950RG, specifically affecting version V4.1.2cu.5204_B20210112. This issue arises in the setNoticeCfg interface within the /lib/cste_modules/system.so library, where improper processing of the IpTo parameter can lead to unauthorized command execution. Attackers exploiting this vulnerability could gain control over the device, potentially leading to network compromise and exploitation of connected systems.