Severity
8.8HIGH
EPSS
0.1%
top 67.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29
Latest updateSep 2

Description

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252269 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respon

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

CVEListV5totolink/n200re9.3.5u.6139_B20201216
NVDtotolink/n200re_firmware9.3.5u.6139_b20201216

🔴Vulnerability Details

3
GHSA
fugit parse and parse_nat stall on lengthy input2024-08-19
CVEList
Totolink N200RE cstecgi.cgi setTracerouteCfg stack-based overflow2024-01-29
GHSA
GHSA-qrpx-55hc-9pr8: A vulnerability was found in Totolink N200RE 92024-01-29

💥Exploits & PoCs

2
Exploit-DB
Typecho 1.3.0 - Race Condition2025-04-10
Nuclei
Jenkins < 2.441 - Arbitrary File Read

📋Vendor Advisories

21
Chrome
Stable Channel Update for Desktop: CVE-2025-129082025-09-02
Chrome
Stable Channel Update for Desktop: CVE-2025-98652025-09-02
Chrome
Stable Channel Update for Desktop: CVE-2025-50652025-05-27
Chrome
Stable Channel Update for Desktop: CVE-2025-40522025-04-29
Chrome
Stable Channel Update for Desktop: CVE-2025-30672025-04-01

🕵️Threat Intelligence

2
Huntress
Vulnerability Reproduced: Immediately Patch ScreenConnect 23.9.8 | Huntress2024-02-19
Huntress
Vulnerability Reproduced: Immediately Patch ScreenConnect 23.9.8 | Huntress

💬Community

1
HackerOne
CVE-2024-2398: HTTP/2 push headers memory-leak2024-04-22
CVE-2024-1000 (HIGH CVSS 8.8) | A vulnerability was found in Totoli | cvebase.io