Vulnerability Description
A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument command leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | T6 Firmware | v4.1.5cu.748_b20211015 |
| Totolink | T6 | 3 |
Related Weaknesses (CWE)
References
- https://github.com/ElvisBlue/Public/blob/main/Vuln/3.mdExploitThird Party Advisory
- https://github.com/ElvisBlue/Public/blob/main/Vuln/3.md#pocExploitThird Party Advisory
- https://vuldb.com/?ctiid.316222Permissions Required
- https://vuldb.com/?id.316222Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.612936Third Party AdvisoryVDB Entry
- https://www.totolink.net/Product
- https://youtu.be/GawLaYfTwYsExploit
- https://github.com/ElvisBlue/Public/blob/main/Vuln/3.md#pocExploitThird Party Advisory
FAQ
What is CVE-2025-7525?
CVE-2025-7525 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the compo...
How severe is CVE-2025-7525?
CVE-2025-7525 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-7525?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink T6 Firmware, Totolink T6.