CVE-2025-8181

A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.conf of the component FTP Service. The manipulation leads to least privilege violation. It is possible to initiate the attack remotely.
References
Link Resource
https://vuldb.com/?ctiid.317595 Permissions Required VDB Entry
https://vuldb.com/?id.317595 Third Party Advisory VDB Entry
https://vuldb.com/?submit.621966 Third Party Advisory VDB Entry
https://vuldb.com/?submit.621968 Third Party Advisory VDB Entry
https://www.notion.so/23a54a1113e780c08f3acca6a746d732 Exploit Third Party Advisory
https://www.totolink.net/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:n600r_firmware:4.3.0:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n600r:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:totolink:x2000r_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x2000r:-:*:*:*:*:*:*:*

History

09 Oct 2025, 19:40

Type Values Removed Values Added
CPE cpe:2.3:o:totolink:n600r_firmware:4.3.0:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x2000r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:x2000r_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n600r:-:*:*:*:*:*:*:*
References () https://vuldb.com/?ctiid.317595 - () https://vuldb.com/?ctiid.317595 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.317595 - () https://vuldb.com/?id.317595 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.621966 - () https://vuldb.com/?submit.621966 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.621968 - () https://vuldb.com/?submit.621968 - Third Party Advisory, VDB Entry
References () https://www.notion.so/23a54a1113e780c08f3acca6a746d732 - () https://www.notion.so/23a54a1113e780c08f3acca6a746d732 - Exploit, Third Party Advisory
References () https://www.totolink.net/ - () https://www.totolink.net/ - Product
First Time Totolink n600r
Totolink x2000r
Totolink
Totolink n600r Firmware
Totolink x2000r Firmware

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad clasificada como crítica en TOTOLINK N600R y X2000R 1.0.0.1. Esta afecta a una parte desconocida del archivo vsftpd.conf del componente Servicio FTP. La manipulación provoca una violación del mínimo privilegio. El ataque puede ejecutarse en remoto.

26 Jul 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-26 07:15

Updated : 2025-10-09 19:40


NVD link : CVE-2025-8181

Mitre link : CVE-2025-8181

CVE.ORG link : CVE-2025-8181


JSON object : View

Products Affected

totolink

  • n600r
  • x2000r_firmware
  • n600r_firmware
  • x2000r
CWE
CWE-266

Incorrect Privilege Assignment

CWE-272

Least Privilege Violation