CRITICAL🇵🇱 Wersja polska

CVE-2025-51452

CVSS 9.8v3.1pub. 2025-08-13upd. 2026-07-05

In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

🤖 AI Analysis
How it works

An attacker sends a specially crafted HTTP request to the formLoginAuth.htm endpoint, which results in bypassing the user identity verification procedure (CWE-288: Authentication Bypass Using an Alternate Path or Channel). The attack requires no privileges or user interaction and can be performed remotely over the network. The authentication mechanism in firmware version 9.1.0u.6115_B20201022 does not properly validate requests directed to this resource.

Impact

An attacker gains unauthorized access to the router's administrative interface, enabling full control over the device — including changing network configuration, intercepting network traffic, and potentially using the router as an entry point to the internal network. CVSS indicators point to a high impact on system confidentiality, integrity, and availability.

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is recommended to check the availability of updated firmware on the TOTOLINK manufacturer's website. Until the update is applied, restrict access to the router's administrative interface only to trusted hosts and disable exposure of the administrative panel on the WAN interface.

Who is affected

TOTOLINK A7000R with firmware version 9.1.0u.6115_B20201022

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Totolink A7000r

    HW
    Totolink
    all versions
  • Totolink A7000r Firmware

    OS
    Totolink
    9.1.0u.6115_b20201022
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-28639CRITICAL9.8PL ✓same product

Buffer Overflow w TOTOLINK X5000R i A7000R — RCE przez pole IP

CVE-2023-49418CRITICAL9.8PL ✓same product

Stack overflow w TOTOLink A7000R via setIpPortFilterRules — RCE bez uwierzytelnienia

CVE-2023-49417CRITICAL9.8PL ✓same product

Stack overflow w TOTOLink A7000R — funkcja setOpModeCfg

CVE-2023-45984CRITICAL9.8PL ✓same product

Stack overflow w TOTOLINK X5000R i A7000R — parametr lang w setLanguageCfg

CVE-2023-36947CRITICAL9.8PL ✓same product

Stack overflow w TOTOLINK X5000R i A7000R — funkcja UploadCustomModule