CVE-2025-60336: Totolink n600r Firmware

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Affected products

  • Totolink n600r Firmware: version 4.3.0cu.7866_b20220506 only

Published 2025-10-22. Last modified 2026-06-17.