CVE-2025-8181

A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.conf of the component FTP Service. The manipulation leads to least privilege violation. It is possible to initiate the attack remotely.
References
Link Resource
https://vuldb.com/?ctiid.317595 Permissions Required VDB Entry
https://vuldb.com/?id.317595 Third Party Advisory VDB Entry
https://vuldb.com/?submit.621966 Third Party Advisory VDB Entry
https://vuldb.com/?submit.621968 Third Party Advisory VDB Entry
https://www.notion.so/23a54a1113e780c08f3acca6a746d732 Exploit Third Party Advisory
https://www.totolink.net/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:n600r_firmware:4.3.0:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n600r:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:totolink:x2000r_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x2000r:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-07-26 07:15

Updated : 2025-10-09 19:40


NVD link : CVE-2025-8181

Mitre link : CVE-2025-8181

CVE.ORG link : CVE-2025-8181


JSON object : View

Products Affected

totolink

  • x2000r_firmware
  • n600r_firmware
  • x2000r
  • n600r
CWE
CWE-266

Incorrect Privilege Assignment

CWE-272

Least Privilege Violation