CVE-2025-55895: Critical severity TOTOLINK A3300R vulnerability
TOTOLINK A3300R V17.0.0cu.557B20221024 and N200RE V9.3.5u.6448B20240521 and V9.3.5u.6437B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55895?
CVE-2025-55895 has a medium severity rating due to its potential for unauthorized access.
How do I fix CVE-2025-55895?
To fix CVE-2025-55895, update the firmware of the TOTOLINK A3300R and N200RE to the latest version provided by the vendor.
What impact does CVE-2025-55895 have on my network?
CVE-2025-55895 allows attackers to exploit incorrect access control, enabling unauthorized actions on affected devices.
Are all versions of TOTOLINK A3300R and N200RE affected by CVE-2025-55895?
Yes, specific versions of the TOTOLINK A3300R and N200RE are vulnerable to CVE-2025-55895, including A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521.
Can CVE-2025-55895 be exploited remotely?
Yes, CVE-2025-55895 can be exploited remotely, as attackers can send malicious payloads without requiring a login.