CVE-2025-4461: TOTOLINK N150RT Virtual Server Page cross site scripting
Published May 9, 2025
·Updated
A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525. This vulnerability affects unknown code of the component Virtual Server Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
TOTOLINK N150RT
All of the following
TOTOLINK N150rt Firmware=3.4.0-b20190525
TOTOLINK N150RT
Event History
May 9, 2025
CVE Published
via MITRE·04:31 AM
Data Sourced
via MITRE·04:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-4461?
CVE-2025-4461 is classified as a problematic vulnerability.
2
How do I fix CVE-2025-4461?
To fix CVE-2025-4461, update the TOTOLINK N150RT firmware to the latest version provided by the vendor.
3
What type of vulnerability is CVE-2025-4461?
CVE-2025-4461 is a cross-site scripting (XSS) vulnerability.
4
Can CVE-2025-4461 be exploited remotely?
Yes, the exploit for CVE-2025-4461 can be initiated remotely.
5
Which devices are affected by CVE-2025-4461?
CVE-2025-4461 affects the TOTOLINK N150RT router with firmware version 3.4.0-B20190525.