CVE-2025-60684: Buffer Overflow

Published Nov 13, 2025
·
Updated

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619B20230130) and NR1800X (V9.1.0u.6681B20230703) Router firmware within the cstecgi.cgi binary (sub42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings using sprintf() into fixed-size stack buffers without proper length validation. Maliciously crafted input can overflow these buffers, potentially leading to arbitrary code execution or memory corruption, without requiring authentication.

Affected Software

6 affected components
TOTOLINK LR1200GB
TOTOLINK NR1800X
All of the following
TOTOLINK Lr1200gb Firmware=9.1.0u.6619_b20230130
TOTOLINK LR1200GB
All of the following
TOTOLINK Nr1800x Firmware=9.1.0u.6681_b20230703
TOTOLINK NR1800X

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ToToLink LR1200GB to a version that resolves this vulnerability.

    Fixed in V9.1.0u.6619_B20230130
  2. Upgrade

    Upgrade ToToLink NR1800X to a version that resolves this vulnerability.

    Fixed in V9.1.0u.6681_B20230703
  3. Configuration

    Update cstecgi.cgi so the web interface validates the length of the 'lang' parameter and uses bounded formatting to prevent stack buffer overflow in help URL string construction.

    ToToLink router web interface (cstecgi.cgi) lang parameter handling (bounds validation before sprintf into fixed-size stack buffers) = Enforce strict length validation and safe formatting (do not use sprintf into fixed-size stack buffers without proper bounds checking)

Event History

Nov 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-60684?

CVE-2025-60684 is rated as a high severity vulnerability due to potential exploit risks associated with stack buffer overflow.

2

How do I fix CVE-2025-60684?

To fix CVE-2025-60684, it is recommended to update the firmware of ToToLink LR1200GB and NR1800X routers to the latest patched version provided by the vendor.

3

Which devices are affected by CVE-2025-60684?

CVE-2025-60684 affects ToToLink LR1200GB and NR1800X router models running specific firmware versions.

4

What is the impact of CVE-2025-60684?

Exploitation of CVE-2025-60684 could allow an attacker to execute arbitrary code on the affected devices.

5

Is CVE-2025-60684 remotely exploitable?

Yes, CVE-2025-60684 can be remotely exploited through the web interface of the affected ToToLink routers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203