CVE-2025-3249: TOTOLINK A6000R mtkwifi.lua apcli_cancel_wps command injection
A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apclicancelwps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3249?
CVE-2025-3249 is classified as a critical vulnerability.
What kind of attack is possible with CVE-2025-3249?
CVE-2025-3249 allows for command injection attacks through the affected function.
What function is affected by CVE-2025-3249?
The function apcli_cancel_wps in the file /usr/lib/lua/luci/controller/mtkwifi.lua is affected by CVE-2025-3249.
How do I fix CVE-2025-3249?
To fix CVE-2025-3249, ensure you update your TOTOLINK A6000R to the latest firmware version.
Which devices are impacted by CVE-2025-3249?
CVE-2025-3249 specifically affects the TOTOLINK A6000R firmware version 1.0.1-B20201211.2000.