PT-2025-16378 · Totolink · Totolink N600R

Xyqer1

·

Published

2025-04-12

·

Updated

2025-04-22

·

CVE-2025-22903

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK N600R version 4.3.0cu.7647 B20210106
Description A stack overflow issue was discovered via the pin parameter in the setWiFiWpsConfig() function.
Recommendations For TOTOLINK N600R version 4.3.0cu.7647 B20210106, consider disabling the setWiFiWpsConfig() function until a patch is available to prevent potential exploitation. Restrict access to the pin parameter in the affected function to minimize the risk of exploitation.

Exploit

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-05797
CVE-2025-22903

Affected Products

Totolink N600R