CVE-2025-67445: High severity TOTOLINK X5000R vulnerability
TOTOLINK X5000R V9.1.0cu.2415B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENTLENGTH environment variable and allocates memory using malloc (CONTENTLENGTH + 1) without sufficient bounds checking. When lighttpd s request size limit is not enforced, a crafted large POST request can cause memory exhaustion or a segmentation fault, leading to a crash of the management CGI and loss of availability of the web interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67445?
CVE-2025-67445 is classified as a denial-of-service vulnerability.
How do I fix CVE-2025-67445?
To address CVE-2025-67445, it is recommended to update the TOTOLINK X5000R firmware to a version that patches this vulnerability.
What causes the denial-of-service in CVE-2025-67445?
The denial-of-service in CVE-2025-67445 occurs due to improper handling of the CONTENT_LENGTH environment variable during memory allocation.
Which software versions are affected by CVE-2025-67445?
CVE-2025-67445 affects TOTOLINK X5000R firmware version V9.1.0cu.2415_B20250515.
Is CVE-2025-67445 being actively exploited?
As of now, there have been no public reports indicating that CVE-2025-67445 is actively being exploited.