Buffer Overflow in TOTOLINK T10 4.1.8cu.5207 Affected by Remote Exploit
CVE-2025-6138
Key Information:
Badges
What is CVE-2025-6138?
A buffer overflow vulnerability exists in the TOTOLINK T10 router's HTTP POST request handler specifically in the 'setWizardCfg' function. By manipulating the 'ssid5g' parameter, attackers can execute remote code, leading to potential unauthorized access to the system. The flaw has been disclosed publicly, raising significant security concerns for users of this product. Implementing necessary updates and patches is critical to safeguard against potential exploits.
Affected Version(s)
T10 4.1.8cu.5207
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved