TOTOLINK T6 HTTP POST Request cstecgi.cgi setTracerouteCfg command injection

CVE Details

Basic Information

Title TOTOLINK T6 HTTP POST Request cstecgi.cgi setTracerouteCfg command injection
Type cve
Published 2025-07-13T09:32:07.316Z
Modified 2025-07-13T09:32:07.316Z

Product Information

Vendor TOTOLINK
Product T6
Version 4.1.5cu.748_B20211015

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A command injection vulnerability in the TOTOLINK T6 router allows remote attackers to execute arbitrary commands via the setTracerouteCfg function in the HTTP POST handler.
AI Severity High
AI Vendor TOTOLINK
AI Product TOTOLINK T6
AI Version 4.1.5cu.748_B20211015

Affected Products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Additional Information

CWE List CWE-77, CWE-74
Source VulDB

Description

A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument command leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.