First published: Fri Feb 21 2025(Updated: )
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOLINK X5000R firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25604 has been classified as a high-severity vulnerability due to its potential for remote command injection.
To fix CVE-2025-25604, update the Totolink X5000R firmware to the latest version provided by the vendor.
Exploitation of CVE-2025-25604 may allow an attacker to execute arbitrary commands on the affected device.
Yes, CVE-2025-25604 can be exploited remotely if the affected device is accessible over the network.
The vulnerability in CVE-2025-25604 specifically affects the vif_disable function in mtkwifi.lua.