TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).
References
| Link | Resource |
|---|---|
| https://github.com/l0tk3/CVES/blob/main/CVE-2025-55895.pdf | Exploit Third Party Advisory |
| https://www.totolink.net/ | Product |
Configurations
History
No history.
Information
Published : 2025-12-15 21:15
Updated : 2025-12-17 19:21
NVD link : CVE-2025-55895
Mitre link : CVE-2025-55895
CVE.ORG link : CVE-2025-55895
JSON object : View
Products Affected
totolink
- n200re_firmware
- a3300r_firmware
- n200re
- a3300r
CWE
CWE-284
Improper Access Control
