PT-2025-43896 · Totolink · Totolink A3300R

Wxhwxhwxh_Mie

·

Published

2025-10-12

·

Updated

2025-10-27

·

CVE-2025-12240

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3300R version 17.0.0cu.557 B20221024
Description A security issue exists in TOTOLINK A3300R 17.0.0cu.557 B20221024. The setDmzCfg function within the /cgi-bin/cstecgi.cgi file is susceptible to a buffer overflow when the ip argument is manipulated. This allows for remote exploitation. The exploit for this issue has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13500
CVE-2025-12240

Affected Products

Totolink A3300R