CVE-2025-5903
published 2025-06-10CVE-2025-5903: A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file…
PriorityP271high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
7.24%
93.6th percentile
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | t10 | — | — |
| totolink | t10_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandPOST /cgi-bin/cstecgi.cgi with body containing topicurl=setWiFiAclRules and desc= parameter value >= 100 characters
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Totolink setWiFiAclRules desc Parameter Buffer Overflow Attempt (CVE-2025-5903)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:20; content:"/cgi-bin/cstecgi.cgi"; http.request_body; content:"topicurl|3d|setWiFiAclRules"; fast_pattern; content:"desc|3d|"; pcre:"/^[^\x2c\x7d$]{100,}(?:\x2c|\x7d|$)/R"; reference:url,candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiAclRules-20bdf0aa118580399a8df6ba2a44c197; reference:cve,2025-5903; classtype:web-application-attack; sid:2062871; rev:2; metadata:affected_product TOTOLINK, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_06_10, cve CVE_2025_5903, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag AI_Generated_Description, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_10_01, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)- →Match HTTP POST requests to /cgi-bin/cstecgi.cgi (exact URI length 20 bytes) with request body containing topicurl=setWiFiAclRules and a desc= parameter value of 100 or more characters not containing comma (0x2c) or closing brace (0x7d).
- →The attack is plaintext (non-TLS) and targets inbound traffic to the home/internal network; deploy the Snort/Suricata rule at the perimeter and internally.
- →MITRE mapping: Initial Access (TA0001) via Exploit Public-Facing Application (T1190).
- ·Affected product is TOTOLINK T10 firmware version 4.1.8cu.5207 only; scope detection rules accordingly.
- ·The Snort rule (sid:2062871 rev:2) uses a PCRE match on the desc parameter; ensure your IDS/IPS engine supports Suricata-style sticky buffer keywords (http.method, http.uri, http.request_body) for correct evaluation.
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Totolink setWiFiAclRules desc Parameter Buffer Overflow Attempt (CVE-2025-5903)
suricata·2025-06-10·CVSS 7.4
CVE-2025-5903 [HIGH] ET WEB_SPECIFIC_APPS Totolink setWiFiAclRules desc Parameter Buffer Overflow Attempt (CVE-2025-5903)
ET WEB_SPECIFIC_APPS Totolink setWiFiAclRules desc Parameter Buffer Overflow Attempt (CVE-2025-5903)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Totolink setWiFiAclRules desc Parameter Buffer Overflow Attempt (CVE-2025-5903)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:20; content:"/cgi-bin/cstecgi.cgi"; http.request_body; content:"topicurl|3d|setWiFiAclRules"; fast_pattern; content:"desc|3d|"; pcre:"/^[^\x2c\x7d$]{100,}(?:\x2c|\x7d|$)/R"; reference:url,candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiAclRules-20bdf0aa118580399a8df6ba2a44c197; reference:cve,2025-5903; classtype:web-application-attack; sid:2062871; rev:2; metadata:affected_product TOTOLINK, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_06_10
No public exploits indexed.
No writeups or analysis indexed.
https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiAclRules-20bdf0aa118580399a8df6ba2a44c197https://vuldb.com/?ctiid.311676https://vuldb.com/?id.311676https://vuldb.com/?submit.592247https://www.totolink.net/https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiAclRules-20bdf0aa118580399a8df6ba2a44c197
2025-06-10
Published