CVE-2025-45798: Totolink a950rg Firmware
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter.
Affected products
- Totolink a950rg Firmware: version 4.1.2cu.5204_b20210112 only
Published 2025-05-08. Last modified 2026-06-17.