PT-2025-20394 · Totolink · Totolink Nr1800X

·

CVE-2025-45845

·

Published

2025-04-08

·

Updated

2025-05-16

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK NR1800X version 9.1.0u.6681 B20230703
Description The issue is an authenticated stack overflow that occurs via the ssid5g parameter in the setWiFiEasyGuestCfg function. This allows for potential exploitation.
Recommendations For TOTOLINK NR1800X version 9.1.0u.6681 B20230703, consider disabling the setWiFiEasyGuestCfg function until a patch is available to prevent exploitation through the ssid5g parameter.

Exploit

Fix

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05626
CVE-2025-45845

Affected Products

Totolink Nr1800X