CVE-2025-7615: TOTOLINK T6 HTTP POST Request cstecgi.cgi clearPairCfg command injection
A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the function clearPairCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7615?
CVE-2025-7615 is classified as a critical vulnerability.
How does CVE-2025-7615 impact TOTOLINK T6 devices?
CVE-2025-7615 allows for command injection through the manipulation of the argument ip in the clearPairCfg function.
How do I fix CVE-2025-7615?
To mitigate CVE-2025-7615, it is recommended to update the TOTOLINK T6 firmware to the latest version provided by the vendor.
Is CVE-2025-7615 remotely exploitable?
Yes, CVE-2025-7615 can be exploited remotely due to its nature involving an HTTP POST request handler.
What software versions are affected by CVE-2025-7615?
CVE-2025-7615 affects TOTOLINK T6 version 4.1.5cu.748.