CVE-2025-4496: Totolink a3000ru Firmware

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Totolink a3000ru Firmware: version 4.1.8cu.5241_b20210927 only
  • Totolink a3100r Firmware: version 4.1.8cu.5241_b20210927 only
  • Totolink a800r Firmware: version 4.1.8cu.5241_b20210927 only
  • Totolink a810r Firmware: version 4.1.8cu.5241_b20210927 only
  • Totolink a950rg Firmware: version 4.1.8cu.5241_b20210927 only
  • Totolink n600r Firmware: version 4.1.8cu.5241_b20210927 only
  • Totolink t10 Firmware: version 4.1.8cu.5241_b20210927 only

Published 2025-05-10. Last modified 2026-06-17.