Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-5904

Опубликовано: 10 июн. 2025
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument device_name leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:totolink:t10_firmware:4.1.8cu.5207:*:*:*:*:*:*:*
cpe:2.3:h:totolink:t10:-:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00141
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119
CWE-120

Связанные уязвимости

CVSS3: 8.8
github
10 дней назад

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument device_name leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 35%
0.00141
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119
CWE-120