CVE-2025-8170: TOTOLINK T6 MQTT Packet meshSlaveDlfw tcpcheck_net buffer overflow
A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748B20211015. This vulnerability affects the function tcpchecknet of the file /router/meshSlaveDlfw of the component MQTT Packet Handler. The manipulation of the argument serverIp leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8170?
CVE-2025-8170 is classified as a critical vulnerability.
How does CVE-2025-8170 affect the TOTOLINK T6?
CVE-2025-8170 affects the tcpcheck_net function, leading to a buffer overflow when serverIp arguments are manipulated.
Which version of TOTOLINK T6 is affected by CVE-2025-8170?
TOTOLINK T6 version 4.1.5cu.748_B20211015 is affected by CVE-2025-8170.
What are the potential consequences of exploiting CVE-2025-8170?
Exploitation of CVE-2025-8170 can lead to unauthorized access or control of the affected device due to a buffer overflow.
How can I mitigate the risk associated with CVE-2025-8170?
Mitigation of CVE-2025-8170 can be achieved by applying the latest firmware updates provided by TOTOLINK.