CVE-2025-5901
published 2025-06-09CVE-2025-5901: A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file…
PriorityP269high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.08%
89.5th percentile
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | t10 | — | — |
| totolink | t10_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandPOST /cgi-bin/cstecgi.cgi with body containing "UploadFirmwareFile" and "File" parameter >= 100 chars
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Totolink UploadFirmwareFile File Parameter Buffer Overflow Attempt (CVE-2025-5901)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:20; content:"/cgi-bin/cstecgi.cgi"; http.request_body; content:"|22|UploadFirmwareFile|22|"; fast_pattern; content:"|22|File|22|"; pcre:"/^[^\x2c\x7d$]{100,}(?:\x2c|\x7d|$)/R"; reference:url,candle-throne-f75.notion.site/TOTOLINK-T10-UploadCustomModule-20bdf0aa118580d59961cd545582c118; reference:cve,2025-5901; classtype:web-application-attack; sid:2062872; rev:1; metadata:affected_product TOTOLINK, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_06_10, cve CVE_2025_5901, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag AI_Generated_Description, updated_at 2025_06_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)- →Exploit targets the UploadCustomModule/UploadFirmwareFile function via HTTP POST to /cgi-bin/cstecgi.cgi; the 'File' parameter body value exceeding 100 characters (with no comma or closing brace) is the overflow trigger.
- →Traffic is plaintext HTTP (not TLS); deploy detection at perimeter and internal network boundaries.
- →Attack is remotely initiated via POST Request Handler; no authentication context implied — monitor all inbound HTTP POST requests to the CGI endpoint on networking equipment.
- →MITRE mapping: TA0001 Initial Access / T1190 Exploit Public-Facing Application — prioritize perimeter TOTOLINK T10 devices running firmware 4.1.8cu.5207.
- ·The PCRE pattern matches a 'File' parameter value of 100+ characters not containing a comma or closing brace; tune threshold if legitimate large file uploads to this endpoint are expected in your environment.
- ·Affected version is specifically TOTOLINK T10 firmware 4.1.8cu.5207; scope detection to devices running this exact firmware version.
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Totolink UploadFirmwareFile File Parameter Buffer Overflow Attempt (CVE-2025-5901)
suricata·2025-06-10·CVSS 7.4
CVE-2025-5901 [HIGH] ET WEB_SPECIFIC_APPS Totolink UploadFirmwareFile File Parameter Buffer Overflow Attempt (CVE-2025-5901)
ET WEB_SPECIFIC_APPS Totolink UploadFirmwareFile File Parameter Buffer Overflow Attempt (CVE-2025-5901)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Totolink UploadFirmwareFile File Parameter Buffer Overflow Attempt (CVE-2025-5901)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:20; content:"/cgi-bin/cstecgi.cgi"; http.request_body; content:"|22|UploadFirmwareFile|22|"; fast_pattern; content:"|22|File|22|"; pcre:"/^[^\x2c\x7d$]{100,}(?:\x2c|\x7d|$)/R"; reference:url,candle-throne-f75.notion.site/TOTOLINK-T10-UploadCustomModule-20bdf0aa118580d59961cd545582c118; reference:cve,2025-5901; classtype:web-application-attack; sid:2062872; rev:1; metadata:affected_product TOTOLINK, attack_target Networking_Equipment, tls_state plaintext, created_a
No public exploits indexed.
No writeups or analysis indexed.
https://candle-throne-f75.notion.site/TOTOLINK-T10-UploadCustomModule-20bdf0aa118580d59961cd545582c118https://vuldb.com/?ctiid.311674https://vuldb.com/?id.311674https://vuldb.com/?submit.592243https://www.totolink.net/https://candle-throne-f75.notion.site/TOTOLINK-T10-UploadCustomModule-20bdf0aa118580d59961cd545582c118
2025-06-09
Published