CVE-2025-67188: Buffer Overflow
A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204B20210112. The issue resides in the setRadvdCfg interface of the /lib/cstemodules/ipv6.so module. The function fails to properly validate the length of the user-controlled radvdinterfacename parameter, allowing remote attackers to trigger a stack buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67188?
CVE-2025-67188 is rated as a high severity vulnerability due to its potential for exploitation via buffer overflow.
How do I fix CVE-2025-67188?
To fix CVE-2025-67188, update the TOTOLINK A950RG firmware to a version that addresses this buffer overflow issue.
What software versions are affected by CVE-2025-67188?
CVE-2025-67188 affects TOTOLINK A950RG with firmware version 4.1.2cu.5204_B20210112.
What type of vulnerability is CVE-2025-67188?
CVE-2025-67188 is identified as a buffer overflow vulnerability impacting the setRadvdCfg interface.
Can CVE-2025-67188 be exploited remotely?
Yes, CVE-2025-67188 can be exploited remotely by attackers exploiting the inadequate validation of user-controlled input.