CVE-2025-7912: TOTOLINK T6 MQTT Service recvSlaveUpgstatus buffer overflow
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748B20211015. This issue affects the function recvSlaveUpgstatus of the component MQTT Service. The manipulation of the argument s leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7912?
CVE-2025-7912 is classified as a critical vulnerability.
How does CVE-2025-7912 affect TOTOLINK T6?
CVE-2025-7912 affects the MQTT Service component, specifically the recvSlaveUpgstatus function, leading to a buffer overflow.
What can an attacker do with CVE-2025-7912?
An attacker can exploit CVE-2025-7912 to initiate a remote attack that may compromise the device.
What versions of the TOTOLINK T6 are affected by CVE-2025-7912?
CVE-2025-7912 affects TOTOLINK T6 running version 4.1.5cu.748_B20211015.
How can I mitigate the risk associated with CVE-2025-7912?
To mitigate the risk, users should apply the latest security patches provided by TOTOLINK for the affected version.