CVE-2025-12259: TOTOLINK A3300R POST Parameter cstecgi.cgi setScheduleCfg stack-based overflow
A flaw has been found in TOTOLINK A3300R 17.0.0cu.557B20221024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component POST Parameter Handler. This manipulation of the argument recHour causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12259?
CVE-2025-12259 has been assigned a high severity level due to its potential for causing a stack-based buffer overflow.
How do I fix CVE-2025-12259?
To fix CVE-2025-12259, update the TOTOLINK A3300R firmware to the latest version provided by the vendor.
What are the potential impacts of CVE-2025-12259?
CVE-2025-12259 can enable an attacker to execute arbitrary code on the device, leading to possible system compromise.
Which devices are affected by CVE-2025-12259?
CVE-2025-12259 affects the TOTOLINK A3300R router running version 17.0.0cu.557_B20221024.
Is CVE-2025-12259 publicly known?
Yes, CVE-2025-12259 is publicly disclosed, and information about it is available from various cybersecurity sources.