CVE-2025-55901: Totolink a3300r Firmware

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.

Affected products

  • Totolink a3300r Firmware: version 17.0.0cu.596_b20250515 only

Published 2025-12-15. Last modified 2026-06-17.