CVE-2025-51452: Critical severity TOTOLINK A7000R vulnerability
Published Aug 13, 2025
·Updated
In TOTOLINK A7000R firmware 9.1.0u.6115B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
Affected Software
3 affected components
TOTOLINK A7000R=9.1.0u.6115_B20201022
All of the following
TOTOLINK A7000R firmware=9.1.0u.6115_b20201022
TOTOLINK A7000R
Event History
Aug 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51452?
CVE-2025-51452 is considered a significant vulnerability due to an attacker being able to bypass authentication.
2
How do I fix CVE-2025-51452?
To fix CVE-2025-51452, update the TOTOLINK A7000R firmware to the latest version that resolves this vulnerability.
3
Who is affected by CVE-2025-51452?
CVE-2025-51452 affects users of the TOTOLINK A7000R firmware version 9.1.0u.6115_B20201022.
4
What type of vulnerability is CVE-2025-51452?
CVE-2025-51452 is an authentication bypass vulnerability.
5
What can an attacker do with CVE-2025-51452?
An attacker can bypass the login mechanism of the TOTOLINK A7000R by sending a specific malicious request.