CVE-2025-7912: Totolink t6 Firmware
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affects the function recvSlaveUpgstatus of the component MQTT Service. The manipulation of the argument s leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected products
- Totolink t6 Firmware: version v4.1.5cu.748_b20211015 only
Published 2025-07-20. Last modified 2026-06-17.