PT-2025-43897 · Totolink · Totolink A3300R

·

CVE-2025-12241

·

Published

2025-10-12

·

Updated

2025-10-28

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A3300R version 17.0.0cu.557 B20221024
Description A flaw exists in TOTOLINK A3300R that allows for remote attacks. The issue is a stack-based buffer overflow within the setLanguageCfg function located in the /cgi-bin/cstecgi.cgi file, specifically in the POST Parameter Handler component. Manipulation of the lang argument triggers this overflow. The exploit for this issue is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13502
CVE-2025-12241

Affected Products

Totolink A3300R