CVE Details
Basic Information
| Title | TOTOLINK T6 HTTP POST Request cstecgi.cgi delDevice command injection |
|---|---|
| Type | cve |
| Published | 2025-07-14T15:02:09.650Z |
| Modified | 2025-07-14T15:02:09.650Z |
Product Information
| Vendor | TOTOLINK |
|---|---|
| Product | T6 |
| Version | 4.1.5cu.748 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A critical command injection vulnerability exists in the TOTOLINK T6 router’s HTTP POST request handler, allowing remote attackers to execute arbitrary commands via the delDevice function. This issue has been publicly disclosed and could be exploited remotely. |
|---|---|
| AI Severity | High |
| AI Vendor | TOTOLINK |
| AI Product | T6 |
| AI Version | 4.1.5cu.748 |
Affected Products
- TOTOLINK T6 4.1.5cu.748
Additional Information
| CWE List | CWE-77, CWE-74 |
|---|---|
| Source | VulDB |
Description
A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ipAddr leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.