CVE-2025-45800

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so library, specifically in the processing of the deviceMac parameter.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5204_b20210112:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:*

History

04 Jun 2025, 17:26

Type Values Removed Values Added
CPE cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5204_b20210112:*:*:*:*:*:*:*
First Time Totolink a950rg
Totolink a950rg Firmware
Totolink
References () https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A950RG/5024-setDeviceName-deviceMac-command.md - () https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A950RG/5024-setDeviceName-deviceMac-command.md - Exploit, Third Party Advisory

12 May 2025, 16:15

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

05 May 2025, 20:54

Type Values Removed Values Added
Summary
  • (es) TOTOLINK A950RG V4.1.2cu.5204_B20210112 contiene una vulnerabilidad de ejecución de comandos en la interfaz setDeviceName de la librería /lib/cste_modules/global.so, específicamente en el procesamiento del parámetro deviceMac.

02 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-02 17:15

Updated : 2025-06-04 17:26


NVD link : CVE-2025-45800

Mitre link : CVE-2025-45800

CVE.ORG link : CVE-2025-45800


JSON object : View

Products Affected

totolink

  • a950rg_firmware
  • a950rg
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')