PT-2025-43897 · Totolink · Totolink A3300R

Yhryhryhr_Tu

·

Published

2025-10-12

·

Updated

2025-10-28

·

CVE-2025-12241

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A3300R version 17.0.0cu.557 B20221024
Description A flaw exists in TOTOLINK A3300R that allows for remote attacks. The issue is a stack-based buffer overflow within the setLanguageCfg function located in the /cgi-bin/cstecgi.cgi file, specifically in the POST Parameter Handler component. Manipulation of the lang argument triggers this overflow. The exploit for this issue is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13502
CVE-2025-12241

Affected Products

Totolink A3300R