CVE-2025-22903: Medium severity totolink n600r vulnerability
Published Apr 15, 2025
·Updated
TOTOLINK N600R V4.3.0cu.7647B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.
Affected Software
3 affected components
TOTOLINK N600R
All of the following
TOTOLINK N600R firmware=4.3.0cu.7647_b20210106
TOTOLINK N600R
Event History
Apr 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22903?
CVE-2025-22903 has a high severity rating due to its potential to exploit a stack overflow vulnerability.
2
How do I fix CVE-2025-22903?
To fix CVE-2025-22903, update the TOTOLINK N600R to the latest firmware version provided by the manufacturer.
3
What systems are affected by CVE-2025-22903?
CVE-2025-22903 specifically affects the TOTOLINK N600R router running version V4.3.0cu.7647_B20210106.
4
What are the potential risks of CVE-2025-22903?
Exploitation of CVE-2025-22903 could allow unauthorized access or control over the affected device.
5
How does CVE-2025-22903 exploit the TOTOLINK N600R?
CVE-2025-22903 exploits the stack overflow issue via the pin parameter in the setWiFiWpsConfig function.