A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
2025-05-10T05:15:50.610
2025-07-29T14:42:19.960
Analyzed
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | a3000ru_firmware | 4.1.8cu.5241_b20210927 | Yes |
Hardware | totolink | a3000ru | - | No |
Operating System | totolink | a810r_firmware | 4.1.8cu.5241_b20210927 | Yes |
Hardware | totolink | a810r | - | No |
Operating System | totolink | t10_firmware | 4.1.8cu.5241_b20210927 | Yes |
Hardware | totolink | t10 | - | No |
Operating System | totolink | a3100r_firmware | 4.1.8cu.5241_b20210927 | Yes |
Hardware | totolink | a3100r | - | No |
Operating System | totolink | a950rg_firmware | 4.1.8cu.5241_b20210927 | Yes |
Hardware | totolink | a950rg | - | No |
Operating System | totolink | a800r_firmware | 4.1.8cu.5241_b20210927 | Yes |
Hardware | totolink | a800r | - | No |
Operating System | totolink | n600r_firmware | 4.1.8cu.5241_b20210927 | Yes |
Hardware | totolink | n600r | - | No |