CVE-2025-60688: Buffer Overflow

Published Nov 13, 2025
·
Updated

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619B20230130) and NR1800X (V9.1.0u.6681B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads the "IpAddress" parameter from a web request and copies it into a fixed-size stack buffer using strcpy() without any length validation. Maliciously crafted input can overflow the buffer, leading to potential arbitrary code execution or memory corruption, without requiring authentication.

Affected Software

6 affected components
TOTOLINK LR1200GB
TOTOLINK NR1800X
All of the following
TOTOLINK Lr1200gb Firmware=9.1.0u.6619_b20230130
TOTOLINK LR1200GB
All of the following
TOTOLINK Nr1800x Firmware=9.1.0u.6681_b20230703
TOTOLINK NR1800X

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ToToLink LR1200GB to a version that resolves this vulnerability.

    Fixed in V9.1.0u.6619_B20230130
  2. Upgrade

    Upgrade ToToLink NR1800X to a version that resolves this vulnerability.

    Fixed in V9.1.0u.6681_B20230703
  3. Configuration

    Modify cstecgi.cgi so the IpAddress web parameter is length-validated (or uses a bounded copy) before copying into the fixed-size stack buffer in setDefResponse; replace strcpy() usage to prevent stack buffer overflow.

    cstecgi.cgi (setDefResponse function) IpAddress input handling = validate length before copying; avoid strcpy() into fixed-size stack buffer

Event History

Nov 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-60688?

CVE-2025-60688 is considered to be a critical vulnerability due to the potential for remote code execution.

2

What software is affected by CVE-2025-60688?

CVE-2025-60688 affects ToToLink LR1200GB and NR1800X router firmware versions V9.1.0u.6619_B20230130 and V9.1.0u.6681_B20230703.

3

How do I fix CVE-2025-60688?

To fix CVE-2025-60688, update to the latest firmware version provided by ToToLink that addresses this vulnerability.

4

How does CVE-2025-60688 exploit work?

CVE-2025-60688 exploits a stack buffer overflow in the cstecgi.cgi binary, allowing attackers to execute arbitrary code.

5

What should I do if I am using affected devices for CVE-2025-60688?

If you are using affected devices, immediately update your firmware to mitigate the risk associated with CVE-2025-60688.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203