CVE-2025-9303

HIGH

TOTOLINK A720R 4.1.5cu.630_B20250509 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument desc results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.320908
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.320908
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.632410
Third Party Advisory, VDB Entry product
https://www.totolink.net/

Scores

CVSS v3 8.8
EPSS 0.0056
EPSS Percentile 68.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
totolink/a720r_firmware 4.1.5cu.630_b20250509
Published Aug 21, 2025
Tracked Since Feb 18, 2026