CVE-2025-5543
Last modified
CVE-2025-5543 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Parent Controls Page. The manipulation of the argument Device Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Totolink | X2000r Firmware | 1.0.0-b20230726.1108 |
References
- https://vuldb.com/?ctiid.310993Permissions Required, Vendor Advisory
- https://vuldb.com/?id.310993Third Party Advisory, Vendor Advisory
- https://vuldb.com/?submit.585728Third Party Advisory, Vendor Advisory
- https://www.totolink.net/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5543?
How severe is CVE-2025-5543?
How do I fix CVE-2025-5543?
Are you affected by CVE-2025-5543?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
