CVE-2025-12260: TOTOLINK A3300R POST Parameter cstecgi.cgi setSyslogCfg stack-based overflow
A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557B20221024. The impacted element is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component POST Parameter Handler. Such manipulation of the argument enable leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12260?
CVE-2025-12260 has not yet been assigned a CVSS score, but it is considered a critical vulnerability due to the potential for remote exploitation via stack-based buffer overflow.
How do I fix CVE-2025-12260?
To remediate CVE-2025-12260, users should update the TOTOLINK A3300R firmware to a version that addresses the buffer overflow vulnerability.
What are the potential exploits of CVE-2025-12260?
Exploitation of CVE-2025-12260 could allow an attacker to execute arbitrary code on the affected device, leading to full system compromise.
Which devices are affected by CVE-2025-12260?
CVE-2025-12260 specifically affects the TOTOLINK A3300R router running firmware version 17.0.0cu.557_B20221024.
Is there a workaround for CVE-2025-12260?
Currently, there are no documented workarounds for CVE-2025-12260, and updating the firmware is the recommended course of action.