github.comexploit
https://github.com/noahze01/IoT-vulnerable/blob/main/TOTOLink/A3300R/setDmzCfg.md CVE-2025-12240
HIGH
TOTOLINK A3300R cstecgi.cgi setDmzCfg buffer overflow
Record summary
CVE-2025-12240 has a selected CVSS score of 8.7 (high).
Description
A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 27, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
A3300RBrowse TOTOLINK / A3300R | CVE List | 17.0.0cu.557_B20221024 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-12240 VDB-329910 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/?ctiid.329910 VDB-329910 | TOTOLINK A3300R cstecgi.cgi setDmzCfg buffer overflowvdb entryTechnical description
https://vuldb.com/?id.329910 Submit #673722 | TOTOLINK A3300R V17.0.0cu.557_B20221024 Buffer OverflowThird-party advisory
https://vuldb.com/?submit.673722 totolink.netproduct
https://www.totolink.net/