Command Injection Vulnerability in TOTOLINK N600R Router
CVE-2025-51390

9.8CRITICAL

Key Information:

Vendor

TOTOLINK

Status
Vendor
CVE Published:
4 August 2025

What is CVE-2025-51390?

The TOTOLINK N600R router version V4.3.0cu.7647_B20210106 is impacted by a command injection vulnerability that allows attackers to exploit the pin parameter in the setWiFiWpsConfig function. By manipulating this parameter, unauthorized users may execute arbitrary commands on the device, potentially compromising the network and leading to unauthorized access to sensitive information. Proper configuration and software updates are essential to mitigate the risk associated with this vulnerability.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.