Severity
7.4HIGH
EPSS
0.3%
top 43.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19

Description

A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the component MQTT Service. The manipulation of the argument dest leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5totolink/t64.1.5cu.748_B20211015
NVDtotolink/t6_firmwarev4.1.5cu.748_b20211015

🔴Vulnerability Details

2
GHSA
GHSA-qxfq-qf96-fww5: A vulnerability was found in TOTOLINK T6 42025-07-19
CVEList
TOTOLINK T6 MQTT Service recvSlaveStaInfo buffer overflow2025-07-19
CVE-2025-7837 (HIGH CVSS 7.4) | A vulnerability was found in TOTOLI | cvebase.io