CVE-2025-60335
7.5TOTOLINK · N600R
A NULL pointer dereference in the main function of TOTOLINK N600R allows unauthenticated attackers to cause a Denial of Service condition via a crafted HTTP request.
Executive summary
A critical NULL pointer dereference vulnerability in TOTOLINK N600R routers allows unauthenticated remote attackers to trigger a Denial of Service, rendering the device unresponsive.
Vulnerability
The vulnerability is a NULL pointer dereference within the main function of the device firmware. An unauthenticated attacker can trigger this flaw by sending a specifically crafted HTTP request to the target device, leading to a crash and subsequent Denial of Service.
Business impact
The ability for an unauthenticated attacker to remotely crash networking equipment presents a significant risk to business continuity. Successful exploitation results in complete service disruption for connected users, which can halt operations and require manual intervention to restore connectivity. With a CVSS score of 7.5, this high-severity flaw necessitates prompt attention to prevent unauthorized service outages.
Remediation
Immediate Action: Since a specific patch is currently unknown, administrators should restrict management interface access to trusted IP addresses only and disable remote management features where possible.
Proactive Monitoring: Monitor device logs for recurring crash events or unusual HTTP traffic patterns directed at the management interface.
Compensating Controls: Deploy a Web Application Firewall or similar network security appliance to filter malformed HTTP requests that might target the vulnerable main function.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced in the CVE record.
Analyst recommendation
Given the availability of a public proof-of-concept and the ease of exploitation, this vulnerability poses a credible threat to organizations utilizing the affected TOTOLINK N600R hardware. Organizations should prioritize isolating these devices from public internet exposure immediately. Please continue to monitor vendor communication channels for the release of an official firmware update to address the root cause of this crash.