CRITICAL🇵🇱 Wersja polska

CVE-2025-46060

CVSS 9.8v3.1pub. 2025-06-13upd. 2026-07-05

Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILENAME component

🤖 AI Analysis
How it works

The vulnerability exists in the UPLOAD_FILENAME component of the TOTOLINK N600R firmware. An attacker sends a crafted request containing an excessively long value in the UPLOAD_FILENAME field, which causes a buffer overflow in accordance with CWE-120. Lack of proper validation of input data length allows overwriting memory areas, which consequently leads to gaining control over the program execution flow.

Impact

An attacker can remotely execute arbitrary code on the device (RCE) without any authentication, gaining full control over the router — including access to sensitive data, ability to modify network configuration, and potential use of the device as a launching point for further attacks.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. Until an update is applied, it is recommended to isolate the device from untrusted networks, block external access to the management interface, and monitor network traffic directed to the device.

Who is affected

TOTOLINK N600R in firmware version 4.3.0cu.7866_B2022506

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Totolink N600r

    HW
    Totolink
    all versions
  • Totolink N600r Firmware

    OS
    Totolink
    4.3.0cu.7866_b2022506
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2025-51390CRITICAL9.8PL ✓same product

Command injection w TOTOLINK N600R via parametr pin (WPS)

CVE-2025-22900CRITICAL9.8PL ✓same product

Stack overflow w Totolink N600R — podatność w funkcji setWanConfig

CVE-2023-43141CRITICAL9.8PL ✓same product

Nieprawidłowa kontrola dostępu w routerach TOTOLINK A3700R i N600R

CVE-2022-28907CRITICAL9.8PL ✓same product

Command Injection w TOTOLINK N600R poprzez funkcję hosttime

CVE-2022-28906CRITICAL9.8PL ✓same product

Command injection w TOTOLINK N600R via parametr langtype