CVE-2025-45800: Command Injection
TOTOLINK A950RG V4.1.2cu.5204B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cstemodules/global.so library, specifically in the processing of the deviceMac parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45800?
CVE-2025-45800 has a high severity due to its potential for command execution.
How do I fix CVE-2025-45800?
To fix CVE-2025-45800, update your TOTOLINK A950RG device to the latest firmware version that addresses this vulnerability.
What systems are affected by CVE-2025-45800?
CVE-2025-45800 specifically affects the TOTOLINK A950RG router with version V4.1.2cu.5204_B20210112.
Can CVE-2025-45800 lead to unauthorized access?
Yes, CVE-2025-45800 can potentially allow attackers to execute commands and gain unauthorized access to the affected device.
What does the command execution vulnerability in CVE-2025-45800 involve?
The command execution vulnerability in CVE-2025-45800 involves the insecure handling of the deviceMac parameter in the setDeviceName interface.