CVE-2025-51452: Totolink a7000r Firmware
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
Affected products
- Totolink a7000r Firmware: version 9.1.0u.6115_b20201022 only
Published 2025-08-13. Last modified 2026-07-05.