CVE-2025-4496: TOTOLINK T10/A3100R/A950RG/A800R/N600R/A3000RU/A810R cstecgi.cgi CloudACMunualUpdate buffer overflow
A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4496?
CVE-2025-4496 has been declared as critical.
How does CVE-2025-4496 affect affected devices?
CVE-2025-4496 affects the function CloudACMunualUpdate in the file /cgi-bin/cstecgi.cgi of the affected TOTOLINK devices.
What devices are affected by CVE-2025-4496?
The vulnerable devices include TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU, and A810R.
How do I fix CVE-2025-4496?
To fix CVE-2025-4496, it is recommended to update to the latest firmware version provided by TOTOLINK.
What type of vulnerability is CVE-2025-4496?
CVE-2025-4496 is a critical vulnerability that allows manipulation of arguments in the CloudACMunualUpdate function.