CVE-2025-2097: TOTOLINK EX1800T cstecgi.cgi setRptWizardCfg stack-based overflow
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112B20220316. This issue affects the function setRptWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument loginpass leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2097?
CVE-2025-2097 is classified as a critical vulnerability due to its potential impact on system security.
How do I fix CVE-2025-2097?
To fix CVE-2025-2097, update the TOTOLINK EX1800T firmware to the latest version provided by the vendor.
What type of vulnerability is CVE-2025-2097?
CVE-2025-2097 is a stack-based buffer overflow vulnerability that can be exploited through the argument loginpass.
Which devices are affected by CVE-2025-2097?
The TOTOLINK EX1800T firmware version 9.1.0cu.2112_B20220316 is affected by CVE-2025-2097.
What are the potential consequences of exploiting CVE-2025-2097?
Exploiting CVE-2025-2097 could allow an attacker to execute arbitrary code, potentially gaining full control over the device.