CVE-2025-45798: Command Injection
A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cstemodules/system.so library, specifically in the processing of the IpTo parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45798?
The severity of CVE-2025-45798 is considered high due to its potential for remote command execution.
How do I fix CVE-2025-45798?
To fix CVE-2025-45798, update the TOTOLINK A950RG firmware to the latest available version provided by the vendor.
What is the impact of CVE-2025-45798?
The impact of CVE-2025-45798 allows an attacker to execute arbitrary commands on the affected device remotely.
Which devices are affected by CVE-2025-45798?
CVE-2025-45798 specifically affects the TOTOLINK A950RG with firmware version V4.1.2cu.5204_B20210112.
What component is vulnerable in CVE-2025-45798?
The vulnerable component in CVE-2025-45798 is the setNoticeCfg interface within the /lib/cste_modules/system.so library.