A hidden remote support feature protected by a static...
Moderate severity
Unreviewed
Published
Jul 11, 2025
to the GitHub Advisory Database
•
Updated Jul 14, 2025
Description
Published by the National Vulnerability Database
Jul 11, 2025
Published to the GitHub Advisory Database
Jul 11, 2025
Last updated
Jul 14, 2025
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands with root privileges.
References