CVE-2025-12258: TOTOLINK A3300R POST Parameter cstecgi.cg setOpModeCfg stack-based overflow
A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557B20221024. Impacted is the function setOpModeCfg of the file /cgi-bin/cstecgi.cg of the component POST Parameter Handler. The manipulation of the argument opmode results in stack-based buffer overflow. The attack may be performed from remote.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12258?
CVE-2025-12258 is rated as a high severity vulnerability due to its potential for exploitation leading to stack-based buffer overflow.
How do I fix CVE-2025-12258?
To mitigate CVE-2025-12258, users should update their TOTOLINK A3300R firmware to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2025-12258?
CVE-2025-12258 is a stack-based buffer overflow vulnerability affecting the function setOpModeCfg in the TOTOLINK A3300R device.
What systems are affected by CVE-2025-12258?
CVE-2025-12258 affects the TOTOLINK A3300R version 17.0.0cu.557_B20221024 specifically.
What can attackers do with CVE-2025-12258?
Attackers can exploit CVE-2025-12258 to execute arbitrary code on the affected system through the manipulation of the opmode argument.