CVE-2025-7524: TOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg command injection
A vulnerability was found in TOTOLINK T6 4.1.5cu.748B20211015. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7524?
CVE-2025-7524 is classified as critical due to its potential for command injection.
How do I fix CVE-2025-7524?
Fixing CVE-2025-7524 involves updating the TOTOLINK T6 firmware to a version that addresses this vulnerability.
What are the consequences of CVE-2025-7524?
The exploitation of CVE-2025-7524 can lead to unauthorized command execution on the affected device.
Which component of TOTOLINK T6 is affected by CVE-2025-7524?
CVE-2025-7524 affects the HTTP POST Request Handler in the setDiagnosisCfg function.
What versions of TOTOLINK T6 are impacted by CVE-2025-7524?
CVE-2025-7524 impacts the TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015.