CVSS v3
9.8
CRITICAL
EPSS Score
54.4%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parameters. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parameters. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
Active exploitation of CVE-2025-52046 has not been confirmed. The EPSS score is 54.4%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2025-52046 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string 3.1.
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).