Metrics
Affected Vendors & Products
Wed, 16 Jul 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Totolink
Totolink t6 Totolink t6 Firmware |
|
CPEs | cpe:2.3:h:totolink:t6:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:t6_firmware:v4.1.5cu.748_b20211015:*:*:*:*:*:*:* |
|
Vendors & Products |
Totolink
Totolink t6 Totolink t6 Firmware |
Tue, 15 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Mon, 14 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ipAddr leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | TOTOLINK T6 HTTP POST Request cstecgi.cgi delDevice command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-07-15T19:51:33.281Z
Reserved: 2025-07-13T20:59:22.930Z
Link: CVE-2025-7614

Updated: 2025-07-14T16:42:33.701Z

Status : Analyzed
Published: 2025-07-14T15:15:25.393
Modified: 2025-07-16T14:31:32.970
Link: CVE-2025-7614

No data.