CVE-2025-7758: TOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg buffer overflow
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748B20211015. Affected by this issue is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7758?
CVE-2025-7758 has been classified as a critical vulnerability.
How do I fix CVE-2025-7758?
To fix CVE-2025-7758, update your TOTOLINK T6 device to the latest firmware version beyond 4.1.5cu.748_B20211015.
What component is affected by CVE-2025-7758?
CVE-2025-7758 affects the HTTP POST Request Handler, specifically the function setDiagnosisCfg in the file /cgi-bin/cstecgi.cgi.
What type of issue is CVE-2025-7758?
CVE-2025-7758 is a manipulation vulnerability that exploits an argument in the device's configuration.
Which devices are impacted by CVE-2025-7758?
CVE-2025-7758 impacts the TOTOLINK T6 devices running versions up to and including 4.1.5cu.748_B20211015.