PT-2025-43895 · Totolink · Totolink A3300R

Yhryhryhr_Miemie

·

Published

2025-10-12

·

Updated

2025-10-28

·

CVE-2025-12239

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3300R version 17.0.0cu.557 B20221024
Description A weakness exists in TOTOLINK A3300R. The issue is related to a buffer overflow in the setDdnsCfg function within the /cgi-bin/cstecgi.cgi file. This can be exploited remotely. The exploit has been made publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13499
CVE-2025-12239

Affected Products

Totolink A3300R