PT-2025-30935 · Totolink · Totolink T6

Reisen_1943

·

Published

2025-07-25

·

Updated

2025-07-26

·

CVE-2025-8170

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK T6 version 4.1.5cu.748 B20211015
Description A critical vulnerability exists in the MQTT Packet Handler component of the affected product. The vulnerability is due to a buffer overflow in the tcpcheck net function within the /router/meshSlaveDlfw file. This issue can be exploited remotely by manipulating the serverIp argument. The exploit for this vulnerability has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-10029
CVE-2025-8170

Affected Products

Totolink T6