← Vulnerability feed

Vulnerability record · CVE-2025-55895 · published 15 December 2025

CVE-2025-55895: Totolink a3300r firmware improper access control vulnerability

TTotolink · A3300r Firmware

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).

9.1 CVSS 3.1 Critical EPSS 0.34% · top 75.2% CWE-284 · Improper access control
9.1CVSS 3.1 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-55895 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-31178Totolink a3300r firmware os command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive par…EPSS 1.4%9.8CVE-2026-31181Totolink a3300r firmware os command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr p…EPSS 1.4%9.8CVE-2026-31175Totolink a3300r firmware command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable param…EPSS 1.4%9.8CVE-2026-31177Totolink a3300r firmware os command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive par…EPSS 1.4%9.8CVE-2026-31170Totolink a3300r firmware command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parame…EPSS 1.4%9.8CVE-2025-52046Totolink a3300r firmware command injection vulnerabilityTotolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parame…EPSS 5.5%9.8CVE-2024-24325Totolink a3300r firmware os command injection vulnerabilityTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules …EPSS 1.7%9.8CVE-2024-24326Totolink a3300r firmware os command injection vulnerabilityTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpR…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2025-55895), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.