VYPR
Unrated severityNVD Advisory· Published Apr 4, 2025· Updated Apr 4, 2025

TOTOLINK A6000R mtkwifi.lua apcli_cancel_wps command injection

CVE-2025-3249

Description

A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Affected products

2
  • Totolink/A6000Rllm-create2 versions
    = 1.0.1-B20201211.2000+ 1 more
    • (no CPE)range: = 1.0.1-B20201211.2000
    • (no CPE)range: 1.0.1-B20201211.2000

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.