CVE-2025-60333
7.5TOTOLINK · N600R
A stack overflow vulnerability in the TOTOLINK N600R router allows unauthenticated attackers to trigger a denial of service condition via the wepkey2 parameter.
Executive summary
A critical stack overflow vulnerability in the TOTOLINK N600R router, identified as CVE-2025-60333, allows remote, unauthenticated attackers to cause a denial of service.
Vulnerability
This vulnerability is a stack-based buffer overflow triggered by sending crafted input to the wepkey2 parameter within the setWiFiMultipleConfig function. The vulnerability is exploitable by an unauthenticated attacker over the network.
Business impact
Successful exploitation results in the denial of service of the affected router, which can lead to significant network outages for users relying on the device. Given the CVSS score of 7.5, this high severity flaw poses a risk to operational continuity, especially in environments where these devices manage critical connectivity.
Remediation
Immediate Action: As no official patch is currently confirmed, users should restrict administrative access to the device and disable remote management features to prevent external exploitation.
Proactive Monitoring: Monitor system logs for repeated device reboots or unusual traffic patterns directed at the device configuration interface.
Compensating Controls: Deploy a firewall policy that restricts access to the device management interface to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the research write-up referenced in the CVE record.
Analyst recommendation
Due to the lack of an available firmware patch and the presence of a public proof-of-concept, organizations should treat this vulnerability with high urgency. Administrators must isolate the affected devices from the public internet immediately to mitigate the risk of remote denial of service attacks.