CVE-2023-7221

CRITICAL

Totolink T6 Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

A vulnerability was found in Totolink T6 4.1.9cu.5241_B20210923. It has been classified as critical. This affects the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument v41 leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249855. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.249855
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.249855
Exploit, Third Party Advisory broken-link exploit
https://github.com/jylsec/vuldb/blob/main/TOTOLINK/T6/1/README.md

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
totolink/t6_firmware 4.1.9cu.5241_b20210923
Published Jan 09, 2024
Tracked Since Feb 18, 2026