CVE-2025-7613: TOTOLINK T6 HTTP POST Request cstecgi.cgi CloudSrvVersionCheck command injection
A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function CloudSrvVersionCheck of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7613?
CVE-2025-7613 has been rated as critical due to its potential for command injection.
How do I fix CVE-2025-7613?
To fix CVE-2025-7613, you should update the TOTOLINK T6 firmware to a patched version that addresses this vulnerability.
What impact does CVE-2025-7613 have on affected systems?
CVE-2025-7613 allows an attacker to execute arbitrary commands on the affected system via a specially crafted HTTP POST request.
Which products are affected by CVE-2025-7613?
CVE-2025-7613 affects the TOTOLINK T6 running firmware version 4.1.5cu.748.
Is there a known exploit for CVE-2025-7613?
Yes, CVE-2025-7613 is subject to known exploits that can leverage the command injection vulnerability.