PT-2025-33016 · Totolink · Totolink A7000R

CVE-2025-51452

·

Published

2025-08-13

·

Updated

2025-08-14

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TOTOLINK A7000R firmware version 9.1.0u.6115 B20201022
Description: An attacker can bypass login by sending a specific request through the formLoginAuth.htm endpoint.
Recommendations: Apply a configuration change to restrict access to the formLoginAuth.htm endpoint.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-51452

Affected Products

Totolink A7000R