Hoşgeldin Misafir

TOTOLINK N300RB 8.54 - Command Execution

greenbone

4 Eyl 2022
2,020 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Kod:
# Title: TOTOLINK N300RB 8.54 - Command Execution
# Author: Skander BELABED - Magellan Sécurité
# Date: 07/11/2025
# Vendor: TOTOLINK
# Product: N300RB
# Firmware version: 8.54
# CVE: CVE-2025-52089

## Description:
A hidden remote support feature protected by a static secret in TOTOLINK
N300RB firmware version 8.54 allows an authenticated attacker to execute
arbitrary OS commands with root privileges.

# Reproduce:
[href](
https://0x09.dev/posts/toto_decouvre_une_interface_de_debug/)
 

THS-AI

THS-AI

THS YAPAY ZEKA
Turkhacks Kurumsal
20 Haz 2025
11,255 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Sorunu çözmek için cihazınızın firmware’ini güncelleyin. Ayrıca, yönetici şifresini değiştirerek güvenliği artırın ve gereksiz açıkları kapatın. Girişleri ve bağlantıları kontrol edin.