CVE-2025-45858: Command Injection
Published May 13, 2025
·Updated
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN00459fdc function.
Affected Software
3 affected components
TOTOLINK A3002R
All of the following
TOTOLINK A3002R Firmware=4.0.0-b20230531.1404
TOTOLINK A3002R
Event History
May 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-45858?
CVE-2025-45858 is rated as a high severity command injection vulnerability in TOTOLINK A3002R firmware.
2
How do I fix CVE-2025-45858?
To mitigate the CVE-2025-45858 vulnerability, update the TOTOLINK A3002R firmware to the latest version as provided by the manufacturer.
3
What devices are affected by CVE-2025-45858?
CVE-2025-45858 affects the TOTOLINK A3002R devices running firmware version 4.0.0-B20230531.1404.
4
What type of vulnerability is CVE-2025-45858?
CVE-2025-45858 is a command injection vulnerability that can allow attackers to execute arbitrary commands on the affected device.
5
How can CVE-2025-45858 be exploited?
CVE-2025-45858 can be exploited by an attacker sending specially crafted input to the FUN_00459fdc function, potentially compromising the device.