CVE-2025-46060: Totolink n600r Firmware

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILENAME component

Affected products

  • Totolink n600r Firmware: version 4.3.0cu.7866_b2022506 only

Published 2025-06-13. Last modified 2026-07-05.