Remote Stack-Based Buffer Overflow in TOTOLINK Networking Device
CVE-2025-5600
Key Information:
Badges
What is CVE-2025-5600?
A remote exploitable stack-based buffer overflow has been identified in the TOTOLINK EX1200T 4.1.2cu.5232_B20210713 networking device. This vulnerability resides in the 'setLanguageCfg' function of the '/cgi-bin/cstecgi.cgi' file, where improper handling of the LangType argument can lead to critical memory corruption. Attackers can exploit this issue from remote locations, potentially allowing them to execute arbitrary code or disrupt services. It is crucial for administrators to apply security updates and monitor for unusual activities on affected devices to prevent potential exploitation.
Affected Version(s)
EX1200T 4.1.2cu.5232_B20210713
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved