8.8
CVSSv3

CVE-2025-4496

CVSSv4: 8.7 | CVSSv3: 8.8 | CVSSv2: 9 | VMScore: 970 | EPSS: 0.00086 | KEV: Not Included
Published: 10/05/2025 Updated: 12/05/2025

Vulnerability Summary

Critical Buffer Overflow in TOTOLINK Router Models via Remote CloudACMunualUpdate

A critical vulnerability exists in multiple TOTOLINK router models, including T10, A3100R, A950RG, A800R, N600R, A3000RU, and A810R running firmware version 4.1.8cu.5241_B20210927. The vulnerability is in the CloudACMunualUpdate function within the /cgi-bin/cstecgi.cgi file. By manipulating the FileName argument, an attacker can trigger a buffer overflow. This vulnerability can be exploited remotely, and since the exploit details have been made public, there is a potential risk of active attacks against these router models.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

totolink t10

totolink a3100r

totolink a950rg

totolink a800r

totolink n600r

totolink a3000ru

totolink a810r