CVE-2025-7460: TOTOLINK T6 HTTP POST Request cstecgi.cgi setWiFiAclRules buffer overflow
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748B20211015 and classified as critical. Affected by this vulnerability is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7460?
CVE-2025-7460 is classified as a critical vulnerability.
What component is affected by CVE-2025-7460?
CVE-2025-7460 affects the HTTP POST Request Handler in the TOTOLINK T6 router.
What function is exploited in CVE-2025-7460?
The function setWiFiAclRules is exploited in CVE-2025-7460.
How do I mitigate CVE-2025-7460?
To mitigate CVE-2025-7460, update the TOTOLINK T6 firmware to the latest version provided by the vendor.
What kind of attack can exploit CVE-2025-7460?
CVE-2025-7460 can lead to unauthorized access due to improper handling of the mac argument.