← Back to browse · API

CVE-2025-52046

Severity
CRITICAL
CVSS
9.8
EPSS
0.05177
Risk score
41.01
CISA KEV
No
PoC
No
Published
2025-07-17
Modified
2025-09-15
First seen
2026-08-07
Aliases
EUVD-2025-21783, GHSA-WVGM-RXV8-96HH
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-21783

Description

Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parameters. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.

References