CVE-2025-52089

A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands with root privileges.
References
Link Resource
https://0x09.dev/posts/toto_decouvre_une_interface_de_debug/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:n300rb_firmware:8.54:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n300rb:-:*:*:*:*:*:*:*

History

19 Jul 2025, 03:15

Type Values Removed Values Added
References
  • {'url': 'http://n300rb.com', 'tags': ['Broken Link'], 'source': 'cve@mitre.org'}
  • {'url': 'http://totolink.com', 'tags': ['Broken Link'], 'source': 'cve@mitre.org'}

18 Jul 2025, 19:07

Type Values Removed Values Added
CPE cpe:2.3:o:totolink:n300rb_firmware:8.54:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n300rb:-:*:*:*:*:*:*:*
First Time Totolink n300rb
Totolink
Totolink n300rb Firmware
References () http://n300rb.com - () http://n300rb.com - Broken Link
References () http://totolink.com - () http://totolink.com - Broken Link
References () https://0x09.dev/posts/toto_decouvre_une_interface_de_debug/ - () https://0x09.dev/posts/toto_decouvre_une_interface_de_debug/ - Exploit, Third Party Advisory

14 Jul 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 8.8
CWE CWE-78 CWE-306
Summary
  • (es) Una función de soporte remoto oculta protegida por un secreto estático en la versión 8.54 del firmware TOTOLINK N300RB permite que un atacante autenticado ejecute comandos arbitrarios del sistema operativo con privilegios de root.

11 Jul 2025, 20:15

Type Values Removed Values Added
CWE CWE-78
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

11 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 15:15

Updated : 2025-07-19 03:15


NVD link : CVE-2025-52089

Mitre link : CVE-2025-52089

CVE.ORG link : CVE-2025-52089


JSON object : View

Products Affected

totolink

  • n300rb_firmware
  • n300rb
CWE
CWE-306

Missing Authentication for Critical Function