CNNVD-202506-1924 Information
CNNVD ID
CNNVD-202506-1924
Related CVE
- CNNVD Published: 2025-06-16
Description (Chinese)
TOTOLINK T10是中国吉翁电子(TOTOLINK)公司的一款无线网路系统路由器。 TOTOLINK T10存在安全漏洞,该漏洞源于对文件/cgi-bin/cstecgi.cgi中函数setWiFiScheduleCfg的参数desc的错误操作导致缓冲区溢出。
Description (English)
TOTOLINK T10 is a wireless network router of the Chinese company TOTOLINK. There is a security loophole in TOTOLINK T10, which stems from the spilling of the buffer zone as a result of an error in the parameter desc for function settWiFiScheduleCfg in file/cgi-bin/cstecgi.cgi.
Hazard Level
Medium
Vulnerability Type
其他
Affected Vendor
头歌
Published
2025-06-16
Last Modified
2026-02-24
References
https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiScheduleCfg-20ddf0aa11858053a171f052787c202f https://vuldb.com/?ctiid.312606 https://www.totolink.net/ https://vuldb.com/?id.312606 https://vuldb.com/?submit.592911 https://access.redhat.com/security/cve/cve-2025-6137
Patch
https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/172/ids/36.html
Share on: