Metrics
Affected Vendors & Products
Wed, 16 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink
Totolink t6 Totolink t6 Firmware |
|
| CPEs | cpe:2.3:h:totolink:t6:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:t6_firmware:v4.1.5cu.748_b20211015:*:*:*:*:*:*:* |
|
| Vendors & Products |
Totolink
Totolink t6 Totolink t6 Firmware |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Mon, 14 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function CloudSrvVersionCheck of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | TOTOLINK T6 HTTP POST Request cstecgi.cgi CloudSrvVersionCheck command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-07-14T14:44:08.080Z
Updated: 2025-07-14T15:06:28.189Z
Reserved: 2025-07-13T20:59:20.389Z
Link: CVE-2025-7613
Updated: 2025-07-14T15:03:48.351Z
Status : Analyzed
Published: 2025-07-14T15:15:25.183
Modified: 2025-07-16T14:32:05.310
Link: CVE-2025-7613
No data.