CVE-2025-60336
BaseFortify
Publication date: 2025-10-22
Last updated on: 2025-10-24
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| totolink | n600r_firmware | 4.3.0cu.7866_b20220506 |
| totolink | n600r | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-476 | The product dereferences a pointer that it expects to be valid but is NULL. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a NULL pointer dereference in the sub_41773C function of TOTOLINK N600R firmware version 4.3.0cu.7866_B20220506. It allows an attacker to cause a Denial of Service (DoS) by sending a specially crafted HTTP request to the device, which triggers the NULL pointer dereference and disrupts normal operation. [1]
How can this vulnerability impact me? :
The vulnerability can impact you by causing a Denial of Service (DoS) on the affected TOTOLINK N600R device. This means the device could become unresponsive or crash, disrupting network connectivity and availability.