PT-2025-30966 · Totolink · Totolink N600R+1
Tpcchecker
·
Published
2025-07-26
·
Updated
2025-07-26
·
CVE-2025-8181
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TOTOLINK N600R version 1.0.0.1
TOTOLINK X2000R version 1.0.0.1
Description
A critical vulnerability exists in the FTP Service component of the affected products. The issue is related to the manipulation of the
vsftpd.conf file, leading to a least privilege violation. The attack can be initiated remotely.Recommendations
TOTOLINK N600R version 1.0.0.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
TOTOLINK X2000R version 1.0.0.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Totolink N600R
Totolink X2000R