CVE-2025-5905
published 2025-06-10CVE-2025-5905: A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file…
PriorityP271high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
7.41%
93.7th percentile
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument Password leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | t10 | — | — |
| totolink | t10_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiRepeaterCfg-20bdf0aa118580bd8cd0da62d4d2e47f
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Totolink setWiFiRepeaterCfg password Parameter Buffer Overflow Attempt (CVE-2025-5905)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:20; content:"/cgi-bin/cstecgi.cgi"; http.request_body; content:"|22|setWiFiRepeaterCfg|22|"; fast_pattern; content:"|22|password|22|"; pcre:"/^[^\x2c\x7d$]{100,}(?:\x2c|\x7d|$)/R"; reference:url,candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiRepeaterCfg-20bdf0aa118580bd8cd0da62d4d2e47f; reference:cve,2025-5905; classtype:web-application-attack; sid:2062874; rev:1; metadata:affected_product TOTOLINK, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_06_10, cve CVE_2025_5905, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag AI_Generated_Description, updated_at 2025_06_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)- →Exploit targets HTTP POST requests to /cgi-bin/cstecgi.cgi; look for the JSON action field 'setWiFiRepeaterCfg' combined with an oversized 'password' parameter (100+ characters without comma or closing brace) in the request body.
- →The URI path is exactly 20 bytes (/cgi-bin/cstecgi.cgi); use a strict URI length match (bsize:20) to reduce false positives.
- →Attack is plaintext (non-TLS) and should be detected at the network perimeter as well as internally; no TLS inspection required.
- →The vulnerability is in the setWiFiRepeaterCfg function of the POST Request Handler; the manipulation of the 'Password' argument causes a stack/heap buffer overflow exploitable remotely.
- ·Affected version is specifically TOTOLINK T10 firmware 4.1.8cu.5207; detections should be scoped to this device/firmware combination to avoid noise on other TOTOLINK models.
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Totolink setWiFiRepeaterCfg password Parameter Buffer Overflow Attempt (CVE-2025-5905)
suricata·2025-06-10·CVSS 7.4
CVE-2025-5905 [HIGH] ET WEB_SPECIFIC_APPS Totolink setWiFiRepeaterCfg password Parameter Buffer Overflow Attempt (CVE-2025-5905)
ET WEB_SPECIFIC_APPS Totolink setWiFiRepeaterCfg password Parameter Buffer Overflow Attempt (CVE-2025-5905)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Totolink setWiFiRepeaterCfg password Parameter Buffer Overflow Attempt (CVE-2025-5905)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:20; content:"/cgi-bin/cstecgi.cgi"; http.request_body; content:"|22|setWiFiRepeaterCfg|22|"; fast_pattern; content:"|22|password|22|"; pcre:"/^[^\x2c\x7d$]{100,}(?:\x2c|\x7d|$)/R"; reference:url,candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiRepeaterCfg-20bdf0aa118580bd8cd0da62d4d2e47f; reference:cve,2025-5905; classtype:web-application-attack; sid:2062874; rev:1; metadata:affected_product TOTOLINK, attack_target Networking_Equipment, tls_state plaintex
No public exploits indexed.
No writeups or analysis indexed.
https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiRepeaterCfg-20bdf0aa118580bd8cd0da62d4d2e47f?pvs=73https://vuldb.com/?ctiid.311678https://vuldb.com/?id.311678https://vuldb.com/?submit.592265https://www.totolink.net/https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiRepeaterCfg-20bdf0aa118580bd8cd0da62d4d2e47f?pvs=73
2025-06-10
Published