CVE-2025-51390: Command Injection
TOTOLINK N600R V4.3.0cu.7647B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK N600Rto a version that resolves this vulnerability.Fixed in V4.3.0cu.7647_B20210106
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51390?
CVE-2025-51390 has been rated as a critical severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-51390?
To mitigate CVE-2025-51390, update the TOTOLINK N600R firmware to the latest version that addresses the command injection vulnerability.
What is the impact of CVE-2025-51390?
CVE-2025-51390 could allow attackers to execute arbitrary commands on the affected device, compromising its security.
Which devices are affected by CVE-2025-51390?
The vulnerability CVE-2025-51390 specifically affects the TOTOLINK N600R router running the vulnerable firmware version V4.3.0cu.7647_B20210106.
How does CVE-2025-51390 work?
CVE-2025-51390 exploits the command injection vulnerability through the pin parameter in the setWiFiWpsConfig function, enabling unauthorized command execution.