CVE-2025-5504 is a critical command injection vulnerability affecting TOTOLINK X2000R firmware version 1.0.0-B20230726.1108. This flaw, located in the /boafrm/formWsc file, allows for remote command injection through manipulation of the 'peerRptPin' argument. While the CVSS score is 6.3 Medium, indicating a lower impact in terms of confidentiality, integrity, and availability, the vulnerability is easily exploitable remotely with low attack complexity and no user interaction required. Although no public exploit code (Metasploit, Nuclei, ExploitDB) is listed, the exploit has been publicly disclosed, and there is community discussion and media coverage, including reports of a botnet targeting similar n-day flaws.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0-b20230726.1108CPE matchmatch criteria | cpe:2.3:o:totolink:x2000r_firmware:1.0.0-b20230726.1108:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.