PT-2025-17568 · Totolink · Totolink A950Rg+3

Published

2025-04-22

·

Updated

2025-04-24

·

CVE-2025-28029

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TOTOLINK A830R version 4.1.2cu.5182 B20201102 TOTOLINK A950RG version 4.1.2cu.5161 B20200903 TOTOLINK A3000RU version 5.9c.5185 B20201128 TOTOLINK A3100R version 4.1.2cu.5247 B20211129
Description A buffer overflow vulnerability was discovered in the cstecgi.cgi of the affected TOTOLINK devices.
Recommendations For TOTOLINK A830R version 4.1.2cu.5182 B20201102, consider disabling access to the cstecgi.cgi until a patch is available. For TOTOLINK A950RG version 4.1.2cu.5161 B20200903, consider disabling access to the cstecgi.cgi until a patch is available. For TOTOLINK A3000RU version 5.9c.5185 B20201128, consider disabling access to the cstecgi.cgi until a patch is available. For TOTOLINK A3100R version 4.1.2cu.5247 B20211129, consider disabling access to the cstecgi.cgi until a patch is available.

Exploit

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-12683
CVE-2025-28029

Affected Products

Totolink A3000Ru
Totolink A3100R
Totolink A830R
Totolink A950Rg