CVE-2025-6138: TOTOLINK T10 HTTP POST Request cstecgi.cgi setWizardCfg buffer overflow
A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ssid5g leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6138?
CVE-2025-6138 is classified as a critical vulnerability.
What component is affected by CVE-2025-6138?
CVE-2025-6138 affects the HTTP POST Request Handler function setWizardCfg in the file /cgi-bin/cstecgi.cgi.
What type of vulnerability is CVE-2025-6138?
CVE-2025-6138 is a buffer overflow vulnerability.
What version of TOTOLINK T10 is impacted by CVE-2025-6138?
CVE-2025-6138 impacts TOTOLINK T10 firmware version 4.1.8cu.5207.
How do I fix CVE-2025-6138?
To fix CVE-2025-6138, it is recommended to update the TOTOLINK T10 firmware to a secure version provided by the vendor.