CVE-2025-60336
7.5TOTOLINK · N600R
A NULL pointer dereference in the TOTOLINK N600R router allows unauthenticated attackers to trigger a device Denial of Service via a crafted HTTP request.
Executive summary
A critical Denial of Service vulnerability in the TOTOLINK N600R router allows unauthenticated attackers to crash the device through specifically crafted network requests.
Vulnerability
This vulnerability involves a NULL pointer dereference within the sub_41773C function, which can be triggered by an unauthenticated attacker sending a malicious HTTP request to the device.
Business impact
The successful exploitation of this vulnerability results in an immediate Denial of Service, causing the router to crash and rendering network connectivity unavailable for all connected users and services. With a CVSS score of 7.5, the high severity reflects the ease of exploitation, as it requires no authentication and can be executed over the network, leading to significant operational disruption.
Remediation
Immediate Action: Since no official patch is currently confirmed, administrators should restrict access to the device management interface to trusted internal networks only.
Proactive Monitoring: Monitor device uptime and logs for unexpected reboots or service interruptions that may indicate a crash event.
Compensating Controls: Implement a firewall rule to block unsolicited external HTTP traffic directed at the management interface of the N600R router.
Exploitation status
Public Exploit Available: Yes — a proof-of-concept exists as documented in the research write-up referenced by the CVE record.
Analyst recommendation
Given the availability of a proof-of-concept and the ease of triggering a system crash, this vulnerability poses a tangible risk to network availability. Organizations utilizing the affected TOTOLINK hardware should prioritize restricting management access and monitoring for signs of instability while awaiting formal vendor guidance or firmware updates.