CVE-2025-4849Injection in N300rh

Severity
5.3MEDIUMNVD
EPSS
2.4%
top 14.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 18

Description

A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been rated as critical. Affected by this issue is the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument url leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5totolink/n300rh6.1c.1390_B20191101
NVDtotolink/n300rh_firmware6.1c.1390_b20191101

🔴Vulnerability Details

2
CVEList
TOTOLINK N300RH cstecgi.cgi CloudACMunualUpdateUserdata command injection2025-05-18
GHSA
GHSA-7f4f-7v48-7gv6: A vulnerability was found in TOTOLINK N300RH 62025-05-18
CVE-2025-4849 — Injection in Totolink N300rh | cvebase