Metrics
Affected Vendors & Products
Fri, 20 Jun 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Totolink
Totolink t10 Totolink t10 Firmware |
|
CPEs | cpe:2.3:h:totolink:t10:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:t10_firmware:4.1.8cu.5207:*:*:*:*:*:*:* |
|
Vendors & Products |
Totolink
Totolink t10 Totolink t10 Firmware |
Tue, 17 Jun 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
ssvc
|
Mon, 16 Jun 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ssid5g leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
Title | TOTOLINK T10 HTTP POST Request cstecgi.cgi setWizardCfg buffer overflow | |
Weaknesses | CWE-119 CWE-120 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-16T20:31:09.003Z
Updated: 2025-06-17T15:25:12.912Z
Reserved: 2025-06-15T10:52:10.120Z
Link: CVE-2025-6138

Updated: 2025-06-17T15:25:07.624Z

Status : Analyzed
Published: 2025-06-16T21:15:24.323
Modified: 2025-06-20T14:34:32.397
Link: CVE-2025-6138

No data.