CVE-2025-60334

7.5

TOTOLINK · N600R v4

A stack overflow vulnerability in the TOTOLINK N600R v4 router allows unauthenticated remote attackers to trigger a denial of service via a crafted ssid parameter.

Executive summary

A stack overflow vulnerability in the TOTOLINK N600R v4 firmware allows unauthenticated attackers to crash the device and cause a denial of service.

Vulnerability

The device contains a stack overflow within the setWiFiBasicConfig function when processing the ssid parameter, which can be exploited by an unauthenticated attacker to cause a system crash.

Business impact

Successful exploitation results in a persistent denial of service condition, rendering the network device unresponsive and disrupting connectivity for all dependent users and services. While the impact is limited to availability, the CVSS score of 7.5 reflects a high risk due to the ease of exploitation over the network without requiring prior authentication.

Remediation

Immediate Action: Contact the vendor support channels to inquire about firmware updates, as a patch is currently not publicly confirmed for this specific version.

Proactive Monitoring: Monitor network infrastructure logs for unusual traffic patterns or repeated attempts to access administrative configuration parameters.

Compensating Controls: Restrict access to the router administrative interface to trusted internal IP addresses and disable remote management features to reduce the attack surface.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists via the technical write-up published on GitHub.

Analyst recommendation

Given the availability of a proof-of-concept and the unauthenticated nature of this vulnerability, administrators should prioritize isolating affected TOTOLINK devices from the public internet. Apply any available vendor firmware updates immediately upon release to remediate the underlying stack overflow flaw.

More TOTOLINK CVEs

Sources