CVE-2025-6302: TOTOLINK EX1200T cstecgi.cgi setStaticDhcpConfig stack-based overflow
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232B20210713. Affected is the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Comment leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6302?
CVE-2025-6302 is classified as a critical vulnerability due to its potential for exploit through stack-based buffer overflow.
How do I fix CVE-2025-6302?
To fix CVE-2025-6302, update the TOTOLINK EX1200T firmware to the latest version that resolves this vulnerability.
What systems are affected by CVE-2025-6302?
CVE-2025-6302 affects the TOTOLINK EX1200T running the firmware version 4.1.2cu.5232_B20210713.
What type of vulnerability is CVE-2025-6302?
CVE-2025-6302 is a stack-based buffer overflow vulnerability found in the setStaticDhcpConfig function.
Can CVE-2025-6302 be exploited remotely?
Yes, CVE-2025-6302 can be exploited remotely if an attacker manipulates the Comment argument in the affected function.