CVE-2025-6299: TOTOLINK N150RT formWSC os command injection
A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the argument targetAPSsid leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6299?
CVE-2025-6299 is classified as a critical vulnerability.
What is the impact of CVE-2025-6299 on TOTOLINK N150RT?
CVE-2025-6299 allows for OS command injection through the manipulation of the targetAPSsid argument.
How can CVE-2025-6299 be exploited?
CVE-2025-6299 can be exploited remotely by manipulating specific input in the affected software.
How do I fix CVE-2025-6299?
To fix CVE-2025-6299, you should apply the latest firmware update provided by TOTOLINK for the N150RT.
Which software versions are affected by CVE-2025-6299?
CVE-2025-6299 affects TOTOLINK N150RT running version 3.4.0-B20190525.