CVE-2025-5600: TOTOLINK EX1200T cstecgi.cgi setLanguageCfg stack-based overflow
Published Jun 4, 2025
·Updated
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232B20210713. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument LangType leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
TOTOLINK EX1200T
All of the following
TOTOLINK EX1200T firmware=4.1.2cu.5232_b20210713
TOTOLINK EX1200T
Event History
Jun 4, 2025
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionSeverityWeakness
Aug 30, 57482
Event
via FIRST·01:28 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5600?
CVE-2025-5600 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-5600?
CVE-2025-5600 is a stack-based buffer overflow vulnerability.
3
Which device is affected by CVE-2025-5600?
CVE-2025-5600 affects the TOTOLINK EX1200T device.
4
How do I fix CVE-2025-5600?
To fix CVE-2025-5600, update the TOTOLINK EX1200T firmware to the latest version provided by the vendor.
5
What is impacted by the CVE-2025-5600 vulnerability?
The function setLanguageCfg of the file /cgi-bin/cstecgi.cgi is affected by CVE-2025-5600.