TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.Referenceshttps://www.totolink.nethttps://github.com/l0tk3/CVES/blob/main/CVE-2025-55901.pdf