8.8

CVE-2025-52089

Exploit
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands with root privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Totolink ≫ N300rb Firmware Version 8.54
   Totolink ≫ N300rb Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.57% 0.94
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://0x09.dev/posts/toto_decouvre_une_interface_de_debug/
Third Party Advisory
Exploit