CVE-2025-3675: TOTOLINK A3700R cstecgi.cgi setL2tpServerCfg access control
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3675?
CVE-2025-3675 has been rated as critical due to improper access controls.
How do I fix CVE-2025-3675?
To fix CVE-2025-3675, update the TOTOLINK A3700R firmware to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2025-3675?
CVE-2025-3675 is a vulnerability related to improper access controls in the TOTOLINK A3700R firmware.
Can CVE-2025-3675 be exploited remotely?
Yes, CVE-2025-3675 can be exploited remotely, allowing attackers to manipulate affected functions.
Which component is affected by CVE-2025-3675?
The function setL2tpServerCfg in the file /cgi-bin/cstecgi.cgi is affected by CVE-2025-3675.