CVE-2025-3995: TOTOLINK N150RT LAN Settings Page fromStaticDHCP cross site scripting
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /boafrm/fromStaticDHCP of the component LAN Settings Page. The manipulation of the argument Hostname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3995?
CVE-2025-3995 has been classified as a problematic vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-3995?
To fix CVE-2025-3995, it is recommended to update the TOTOLINK N150RT firmware to the latest version provided by the manufacturer.
What are the consequences of exploiting CVE-2025-3995?
Exploiting CVE-2025-3995 could allow an attacker to perform unauthorized actions affecting LAN settings.
Which devices are affected by CVE-2025-3995?
CVE-2025-3995 specifically affects the TOTOLINK N150RT router running version 3.4.0-B20190525.
What component is vulnerable in CVE-2025-3995?
The vulnerable component in CVE-2025-3995 is the LAN Settings Page located at /boafrm/fromStaticDHCP.