CVE Details
Basic Information
| Title |
TOTOLINK EX1200T cstecgi.cgi setLanguageCfg stack-based overflow |
| Type |
cve |
| Published |
2025-06-04T17:31:11.291Z |
| Last Seen |
|
Product Information
| Vendor |
TOTOLINK |
| Product |
EX1200T |
| Version |
4.1.2cu.5232_B20210713 |
CVSS Information
| Base Score |
9.3 (CRITICAL) |
| Attack Vector |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Confidentiality Impact |
|
| Integrity Impact |
|
| Availability Impact |
|
AI Analysis
| AI Description |
A critical stack-based buffer overflow vulnerability in TOTOLINK EX1200T’s setLanguageCfg function allows remote attackers to cause a denial of service or potentially execute arbitrary code. The issue is highly severe due to its remote exploitability and the critical CVSS score of 9.3. |
| AI Severity |
High |
| Vendor |
TOTOLINK |
| Product |
EX1200T |
| Affected Version |
4.1.2cu.5232_B20210713 |
Additional Information
| CVE List |
|
| CWE List |
CWE-121, CWE-119 |
| Bulletin Family |
|
| Source Data |
TOTOLINK EX1200T 4.1.2cu.5232_B20210713 |
Source Information
| Source Data |
TOTOLINK EX1200T 4.1.2cu.5232_B20210713 |
| Source Link |
|
Description
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument LangType leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Score Summary
Base Score: 9.3 (CRITICAL)
View Full CVE Details