CVE-2025-12239: TOTOLINK A3300R cstecgi.cgi setDdnsCfg buffer overflow
A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557B20221024. The impacted element is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Executing manipulation can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12239?
CVE-2025-12239 is classified as a high-severity vulnerability due to the potential for remote exploitation leading to a buffer overflow.
How do I fix CVE-2025-12239?
To fix CVE-2025-12239, update the TOTOLINK A3300R firmware to the latest version provided by the manufacturer.
Who is affected by CVE-2025-12239?
Any user of the TOTOLINK A3300R router running version 17.0.0cu.557_B20221024 is potentially affected by CVE-2025-12239.
What type of vulnerability is CVE-2025-12239?
CVE-2025-12239 is a buffer overflow vulnerability that can be exploited remotely.
Can CVE-2025-12239 be exploited remotely?
Yes, CVE-2025-12239 can be exploited remotely, allowing attackers to potentially take control of the affected device.