CVE-2025-11444

A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the component HTTP Request Handler. Such manipulation of the argument wepkey leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:n600r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:totolink:n600r:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-10-08 08:15

Updated : 2025-10-14 20:16


NVD link : CVE-2025-11444

Mitre link : CVE-2025-11444

CVE.ORG link : CVE-2025-11444


JSON object : View

Products Affected

totolink

  • n600r_firmware
  • n600r
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')