CVE-2025-52046: Command Injection
Published Jul 17, 2025
·Updated
Totolink A3300R V17.0.0cu.596B20250515 was found to contain a command injection vulnerability in the sub4197C0 function via the mac and desc parameters. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
Affected Software
3 affected components
TOTOLINK A3300R
All of the following
TOTOLINK A3300R firmware=17.0.0cu.596_b20250515
TOTOLINK A3300R
Event History
Jul 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52046?
The severity of CVE-2025-52046 is considered high due to its potential for unauthenticated command execution.
2
How do I fix CVE-2025-52046?
To fix CVE-2025-52046, update the Totolink A3300R firmware to the latest version provided by the vendor.
3
What kind of attack does CVE-2025-52046 enable?
CVE-2025-52046 enables unauthorized command injection attacks via crafted requests.
4
Who is affected by CVE-2025-52046?
Users of Totolink A3300R with the specified firmware version are affected by CVE-2025-52046.
5
Can CVE-2025-52046 be exploited remotely?
Yes, CVE-2025-52046 can be exploited remotely by unauthenticated attackers.