CNNVD-202506-1927 Information

CNNVD ID

CNNVD-202506-1927

CVE-2025-6138

  • CNNVD Published: 2025-06-16

Description (Chinese)

TOTOLINK T10是中国吉翁电子(TOTOLINK)公司的一款无线网路系统路由器。 TOTOLINK T10 存在安全漏洞,该漏洞源于对文件/cgi-bin/cstecgi.cgi中函数setWizardCfg的参数ssid5g的错误操作导致缓冲区溢出。

Description (English)

TOTOLINK T10 is a wireless network router of the Chinese company TOTOLINK. TOTOLINK T10 has a security loophole, which stems from the spilling of the buffer zone as a result of the error of the parameter ssid5g for the function setWizardCfg in file/cgi-bin/cstecgi.cgi.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

头歌

Published

2025-06-16

Last Modified

2026-02-24

References

https://vuldb.com/?submit.592917 https://candle-throne-f75.notion.site/TOTOLINK-T10-setWizardCfg-20ddf0aa1185808892f1dbbf63e6a153?pvs=73 https://vuldb.com/?id.312607 https://www.totolink.net/ https://vuldb.com/?ctiid.312607 https://access.redhat.com/security/cve/cve-2025-6138

Patch

https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/172/ids/36.html

Share on: