CVE-2025-4851
Last modified
CVE-2025-4851 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability classified as critical was found in TOTOLINK N300RH 6.1c.1390_B20191101. This vulnerability affects the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. EPSS estimates a 1.49% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical was found in TOTOLINK N300RH 6.1c.1390_B20191101. This vulnerability affects the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Totolink | N300rh Firmware | 6.1c.1390_b20191101 |
References
- https://vuldb.com/?ctiid.309322Permissions Required, VDB Entry
- https://vuldb.com/?id.309322Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.575074Third Party Advisory, VDB Entry
- https://www.totolink.net/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-4851?
How severe is CVE-2025-4851?
How do I fix CVE-2025-4851?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-48503A DLL hijacking vulnerability in the AMD Software Installer …7.8
- CVE-2025-48505Weak permissions in the Vitis™ Unified installation path on …1
- CVE-2025-48506Uncontrolled search paths in Vitis™ Unified installation pat…4.6
- CVE-2025-48507The security state of the calling processor into Trusted Fir…8.6
- CVE-2025-48508Improper Hardware reset flow logic in the GPU GFX Hardware I…6
- CVE-2025-48509Missing Checks in certain functions related to RMP initializ…1.8
- CVE-2025-48510Improper return value within AMD uProf can allow a local att…7.1
- CVE-2025-48511Improper input validation within AMD uprof can allow a local…5.5
- CVE-2025-48512Incorrect default permissions in the installation directory …7
- CVE-2025-48513Use of uninitialized resource within the AMD Platform Manage…6.9
- CVE-2025-48514Insufficient Granularity of Access Control in SEV firmware c…4
- CVE-2025-48515Insufficient parameter sanitization in AMD Secure Processor …5.4
Are you affected by CVE-2025-4851?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
