CVE-2025-6137: TOTOLINK T10 HTTP POST Request cstecgi.cgi setWiFiScheduleCfg buffer overflow
A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6137?
CVE-2025-6137 is classified as a critical vulnerability.
What components are affected by CVE-2025-6137?
CVE-2025-6137 affects the setWiFiScheduleCfg function in the HTTP POST Request Handler of TOTOLINK T10.
How does CVE-2025-6137 exploit the system?
CVE-2025-6137 can lead to a buffer overflow through manipulation of the argument desc.
What versions of TOTOLINK T10 are impacted by CVE-2025-6137?
CVE-2025-6137 affects TOTOLINK T10 running version 4.1.8cu.5207.
How can I mitigate CVE-2025-6137?
To mitigate CVE-2025-6137, it is recommended to apply available firmware updates from TOTOLINK.