CVE-2025-12240: TOTOLINK A3300R cstecgi.cgi setDmzCfg buffer overflow
A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557B20221024. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12240?
CVE-2025-12240 is classified as a high severity vulnerability due to its potential to allow remote code execution through a buffer overflow.
How do I fix CVE-2025-12240?
To fix CVE-2025-12240, update the TOTOLINK A3300R firmware to the latest version provided by the vendor.
What is affected by CVE-2025-12240?
CVE-2025-12240 affects the TOTOLINK A3300R router with firmware version 17.0.0cu.557_B20221024.
Can CVE-2025-12240 be exploited remotely?
Yes, CVE-2025-12240 can be exploited remotely, allowing attackers to manipulate the device without physical access.
What function is vulnerable in CVE-2025-12240?
The setDmzCfg function in the /cgi-bin/cstecgi.cgi file is vulnerable in CVE-2025-12240.