A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
History

Tue, 22 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink a3700r
Totolink a3700r Firmware
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:h:totolink:a3700r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a3700r_firmware:9.1.2u.5822_b20200513:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink a3700r
Totolink a3700r Firmware

Wed, 16 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 07:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Title TOTOLINK A3700R cstecgi.cgi setUrlFilterRules access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-04-16T07:00:11.827Z

Updated: 2025-04-16T13:54:14.666Z

Reserved: 2025-04-16T00:52:28.357Z

Link: CVE-2025-3674

cve-icon Vulnrichment

Updated: 2025-04-16T13:54:09.297Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-16T07:15:42.300

Modified: 2025-04-22T16:52:45.317

Link: CVE-2025-3674

cve-icon Redhat

No data.