First published: Sun Feb 16 2025(Updated: )
A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation as part of String leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOLINK X18 | =9.1.0cu.2024_B20220329 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-1340 is classified as critical due to its potential for remote exploitation.
To fix CVE-2025-1340, it is recommended to update the TOTOLINK X18 firmware to a version that addresses this vulnerability.
An attacker can exploit CVE-2025-1340 through remote manipulation, leading to a stack-based buffer overflow.
CVE-2025-1340 affects the setPasswordCfg function in the /cgi-bin/cstecgi.cgi file.
CVE-2025-1340 affects the TOTOLINK X18 version 9.1.0cu.2024_B20220329.