CVE-2025-7614: TOTOLINK T6 HTTP POST Request cstecgi.cgi delDevice command injection
A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ipAddr leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7614?
CVE-2025-7614 is classified as a critical vulnerability.
How do I fix CVE-2025-7614?
To fix CVE-2025-7614, users should update TOTOLINK T6 to the latest firmware version.
What does CVE-2025-7614 affect?
CVE-2025-7614 affects the function delDevice in the HTTP POST Request Handler of TOTOLINK T6 firmware version 4.1.5cu.748.
What type of vulnerability is CVE-2025-7614?
CVE-2025-7614 is a command injection vulnerability.
Can CVE-2025-7614 be exploited remotely?
Yes, CVE-2025-7614 can be exploited remotely through the manipulation of the ipAddr argument.