Junglewise Threat Intelligence

CVE-2025-51452: TOTOLINK A7000R authentication bypass in formLoginAuth.htm

CVE-2025-51452 · Severity: critical · CVSS 9.8 · Published 2025-08-13

Vendors: TOTOLINK.

Executive brief

A vulnerability in the TOTOLINK A7000R wireless router allows an unauthorized person to bypass the login screen and gain administrative access to the device. By sending a specially crafted web request, an attacker can take full control of the router without needing a password. This could lead to the interception of internet traffic, unauthorized changes to network settings, or a complete disruption of service.

Technical details

An authentication bypass vulnerability (CWE-288) exists in the TOTOLINK A7000R router running firmware version 9.1.0u.6115_B20201022. The flaw is located within the 'formLoginAuth.htm' component, where the device fails to properly validate authentication requests. A remote, unauthenticated attacker can exploit this by sending a specifically crafted HTTP request to the vulnerable endpoint, effectively bypassing the login mechanism. Successful exploitation grants the attacker full administrative privileges over the device's web management interface. While a newer firmware version (V9.1.0u.6268_B20220504) is listed on the manufacturer's site, users should verify if it addresses this specific flaw.

Affected products

  • TOTOLINK A7000R Firmware 9.1.0u.6115_B20201022

Timeline

  • 2025-08-12: disclosed: Initial researcher disclosure on GitHub
  • 2025-08-13: advisory: NVD publication date

References