CVE-2025-7952: TOTOLINK T6 MQTT Packet wireless.so ckeckKeepAlive command injection
A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. This vulnerability affects the function ckeckKeepAlive of the file wireless.so of the component MQTT Packet Handler. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7952?
CVE-2025-7952 is classified as critical due to its potential for remote command injection.
How do I fix CVE-2025-7952?
To fix CVE-2025-7952, update to the latest firmware version provided by TOTOLINK that addresses this vulnerability.
What components are affected by CVE-2025-7952?
CVE-2025-7952 affects the MQTT Packet Handler in the wireless.so file of the TOTOLINK T6 device.
Can CVE-2025-7952 be exploited remotely?
Yes, CVE-2025-7952 can be exploited remotely without requiring physical access to the device.
What kind of attack can be performed using CVE-2025-7952?
The attack vector for CVE-2025-7952 enables command injection through the vulnerable function.