Metrics
Affected Vendors & Products
Thu, 26 Jun 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Totolink
Totolink t10 Totolink t10 Firmware |
|
CPEs | cpe:2.3:h:totolink:t10:2.0:*:*:*:*:*:*:* cpe:2.3:o:totolink:t10_firmware:4.1.8cu.5207_b20210320:*:*:*:*:*:*:* |
|
Vendors & Products |
Totolink
Totolink t10 Totolink t10 Firmware |
Tue, 17 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 16 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | TOTOLINK T10 HTTP POST Request cstecgi.cgi setWiFiScheduleCfg buffer overflow | |
Weaknesses | CWE-119 CWE-120 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-16T20:00:16.269Z
Updated: 2025-06-17T13:53:11.047Z
Reserved: 2025-06-15T10:52:07.984Z
Link: CVE-2025-6137

Updated: 2025-06-17T13:53:07.815Z

Status : Analyzed
Published: 2025-06-16T20:15:28.040
Modified: 2025-06-26T16:33:18.123
Link: CVE-2025-6137

No data.