PT-2025-41240 · Totolink · Totolink N600R

Z472421519

·

Published

2025-10-08

·

Updated

2025-10-13

·

CVE-2025-11444

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK N600R versions prior to 4.3.0cu.7866 B20220506
Description A buffer overflow issue exists in TOTOLINK N600R. The issue is located in the setWiFiBasicConfig function within the /cgi-bin/cstecgi.cgi file of the HTTP Request Handler component. Manipulation of the wepkey argument can trigger the buffer overflow, allowing for remote exploitation. The exploit has been publicly disclosed.
Recommendations Update TOTOLINK N600R to a version newer than 4.3.0cu.7866 B20220506.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-12824
CVE-2025-11444

Affected Products

Totolink N600R