First published: Mon Mar 17 2025(Updated: )
A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316. It has been classified as critical. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument admpass leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink EX1800T | <=9.1.0cu.2112_B20220316 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-2369 is classified as critical due to its potential for exploitation.
To fix CVE-2025-2369, users should update the firmware of TOTOLINK EX1800T to the latest version beyond 9.1.0cu.2112_B20220316.
CVE-2025-2369 is a stack-based buffer overflow vulnerability affecting the setPasswordCfg function in the device's CGI script.
CVE-2025-2369 affects the TOTOLINK EX1800T router with firmware version up to 9.1.0cu.2112_B20220316.
Yes, CVE-2025-2369 could potentially allow for remote code execution due to the buffer overflow vulnerability.