CVE-2025-14964: TOTOLINK T10 cstecgi.cgi sprintf stack-based overflow
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument loginAuthUrl leads to stack-based buffer overflow. The attack may be performed from remote.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14964?
CVE-2025-14964 is classified as a critical vulnerability due to the potential for remote execution through a stack-based buffer overflow.
How do I fix CVE-2025-14964?
To fix CVE-2025-14964, update the TOTOLINK T10 firmware to the latest available version provided by the manufacturer.
Who is affected by CVE-2025-14964?
CVE-2025-14964 affects users of the TOTOLINK T10 router running firmware version 4.1.8cu.5083_B20200521.
What type of vulnerability is CVE-2025-14964?
CVE-2025-14964 is a stack-based buffer overflow vulnerability that can be exploited remotely.
Can CVE-2025-14964 be exploited without local access?
Yes, CVE-2025-14964 can be exploited remotely, allowing attackers to execute malicious code without local access.