CVE-2025-8181
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
26/07/2025
Last modified:
09/10/2025
Description
A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.conf of the component FTP Service. The manipulation leads to least privilege violation. It is possible to initiate the attack remotely.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
8.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:totolink:n600r_firmware:4.3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:totolink:n600r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:totolink:x2000r_firmware:1.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:totolink:x2000r:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



