CVE-2025-52089
HIGH EXPLOITEDTOTOLINK N300RB Firmware 8.54 - Authenticated Remote Code Execution via Hidden Debug Interface
Title source: llmExploitation Summary
CVE-2025-52089 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Skander BELABED - Magellan Sécurité.
AI-analyzed exploit summary This is a writeup describing a hidden remote support feature in TOTOLINK N300RB firmware 8.54 that allows authenticated attackers to execute arbitrary OS commands with root privileges via a static secret. The provided link references additional details but no exploit code is included.
Description
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands with root privileges.
Exploits (1)
This is a writeup describing a hidden remote support feature in TOTOLINK N300RB firmware 8.54 that allows authenticated attackers to execute arbitrary OS commands with root privileges via a static secret. The provided link references additional details but no exploit code is included.
References (1)
Scores
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H