Totolink · Totolink Ex1200T · CVE-2025-6302
**Name of the Vulnerable Software and Affected Versions**
TOTOLINK EX1200T version 4.1.2cu.5232 B20210713
**Description**
A critical issue was found in the setStaticDhcpConfig function of the /cgi-bin/cstecgi.cgi file. The manipulation of the `Comment` argument leads to a stack-based buffer overflow. This issue can be exploited remotely.
**Recommendations**
For TOTOLINK EX1200T version 4.1.2cu.5232 B20210713, as a temporary workaround, consider disabling the `setStaticDhcpConfig` function until a patch is available. Restrict access to the `/cgi-bin/cstecgi.cgi` file to minimize the risk of exploitation. Avoid using the `Comment` argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.