Record summary

CVE-2025-12240 has a selected CVSS score of 8.7 (high).

Description

A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 27, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List17.0.0cu.557_B20221024affected

References

6