First published: Thu May 08 2025(Updated: )
A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOlink A950RG |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-45798 is considered high due to its potential for remote command execution.
To fix CVE-2025-45798, update the TOTOLINK A950RG firmware to the latest available version provided by the vendor.
The impact of CVE-2025-45798 allows an attacker to execute arbitrary commands on the affected device remotely.
CVE-2025-45798 specifically affects the TOTOLINK A950RG with firmware version V4.1.2cu.5204_B20210112.
The vulnerable component in CVE-2025-45798 is the setNoticeCfg interface within the /lib/cste_modules/system.so library.