CVE-2025-55901: Command Injection
Published Dec 15, 2025
·Updated
TOTOLINK A3300R V17.0.0cu.596B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the hosttime parameter.
Affected Software
3 affected components
TOTOLINK A3300R
All of the following
TOTOLINK A3300R firmware=17.0.0cu.596_b20250515
TOTOLINK A3300R
Event History
Dec 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55901?
CVE-2025-55901 has been classified as a high severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2025-55901?
To fix CVE-2025-55901, you should update to the latest firmware version provided by TOTOLINK for the A3300R device.
3
What type of vulnerability is CVE-2025-55901?
CVE-2025-55901 is a command injection vulnerability that affects the NTPSyncWithHost function.
4
Which product is affected by CVE-2025-55901?
CVE-2025-55901 affects the TOTOLINK A3300R router specifically.
5
What is the impact of CVE-2025-55901 on affected systems?
The impact of CVE-2025-55901 includes unauthorized command execution, which can lead to system compromise.