CVE-2025-52089

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
11/07/2025
Last modified:
19/07/2025

Description

A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands with root privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:totolink:n300rb_firmware:8.54:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n300rb:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools