CVE-2025-8181

7.2 HIGH
Published: July 26, 2025 Modified: October 09, 2025

Description

A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.conf of the component FTP Service. The manipulation leads to least privilege violation. It is possible to initiate the attack remotely.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://vuldb.com/?ctiid.317595
Source: cna@vuldb.com
Permissions Required VDB Entry
https://vuldb.com/?id.317595
Source: cna@vuldb.com
Third Party Advisory VDB Entry
https://vuldb.com/?submit.621966
Source: cna@vuldb.com
Third Party Advisory VDB Entry
https://vuldb.com/?submit.621968
Source: cna@vuldb.com
Third Party Advisory VDB Entry
https://www.notion.so/23a54a1113e780c08f3acca6a746d732
Source: cna@vuldb.com
Exploit Third Party Advisory
https://www.totolink.net/
Source: cna@vuldb.com
Product

6 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.2 / 10.0
EPSS (Exploit Probability)
0.4%
58th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

totolink