CVE-2025-9935: TOTOLINK N600R cstecgi.cgi sub_4159F8 command injection
A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866B20220506. This vulnerability affects the function sub4159F8 of the file /webcste/cgi-bin/cstecgi.cgi. Executing manipulation can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9935?
CVE-2025-9935 is considered a high severity vulnerability due to the potential for remote command injection.
How do I fix CVE-2025-9935?
To fix CVE-2025-9935, update the TOTOLINK N600R firmware to the latest version provided by the manufacturer.
What systems are affected by CVE-2025-9935?
CVE-2025-9935 affects the TOTOLINK N600R router running firmware version 4.3.0cu.7866_B20220506.
Can CVE-2025-9935 be exploited remotely?
Yes, CVE-2025-9935 can be exploited remotely by an attacker manipulating specific functions within the router's firmware.
What is the nature of the vulnerability in CVE-2025-9935?
CVE-2025-9935 is a command injection vulnerability that can allow an attacker to execute arbitrary commands on the affected router.