CVE-2025-55893

MEDIUM

TOTOLINK N200RE V9.3.5u.6437_B20230519 - Command Injection

Title source: llm
STIX 2.1

Description

TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0050
EPSS Percentile 66.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (1)
totolink/n200re_firmware 9.3.5u.6437_b20230519
Published Dec 15, 2025
Tracked Since Feb 18, 2026