CVE-2025-45800

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so library, specifically in the processing of the deviceMac parameter.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5204_b20210112:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:*

History

04 Jun 2025, 17:26

Type Values Removed Values Added
References () https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A950RG/5024-setDeviceName-deviceMac-command.md - () https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A950RG/5024-setDeviceName-deviceMac-command.md - Exploit, Third Party Advisory
CPE cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5204_b20210112:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:*
First Time Totolink a950rg Firmware
Totolink a950rg
Totolink

02 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-02 17:15

Updated : 2025-06-04 17:26


NVD link : CVE-2025-45800

Mitre link : CVE-2025-45800


JSON object : View

Products Affected

totolink

  • a950rg_firmware
  • a950rg
CWE

No CWE.