← Vulnerability feed

Vulnerability record · CVE-2025-12241 · published 27 October 2025

CVE-2025-12241: Totolink a3300r firmware memory buffer overflow vulnerability

TTotolink · A3300r Firmware

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This impacts the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Parameter Handler. The manipulation of the argument lang results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.

7.4 CVSS 4.0 High EPSS 0.95% · top 40.4% CWE-119 · Memory buffer overflowCWE-121 · Stack-based buffer overflow
7.4CVSS 4.0 base score, v2 9.0
0.95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This impacts the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Parameter Handler. The manipulation of the argument lang results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/noahze01/IoT-vulnerable/blob/main/TOTOLink/A3300R/setLanguageCfg.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.329911 Permissions RequiredVDB Entry
https://vuldb.com/?id.329911 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.673723 Third Party AdvisoryVDB Entry
https://www.totolink.net/ Product

Track CVE-2025-12241 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-31178Totolink a3300r firmware os command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive par…EPSS 1.4%9.8CVE-2026-31181Totolink a3300r firmware os command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr p…EPSS 1.4%9.8CVE-2026-31175Totolink a3300r firmware command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable param…EPSS 1.4%9.8CVE-2026-31177Totolink a3300r firmware os command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive par…EPSS 1.4%9.8CVE-2026-31170Totolink a3300r firmware command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parame…EPSS 1.4%9.8CVE-2025-52046Totolink a3300r firmware command injection vulnerabilityTotolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parame…EPSS 5.5%9.8CVE-2024-24325Totolink a3300r firmware os command injection vulnerabilityTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules …EPSS 1.7%9.8CVE-2024-24326Totolink a3300r firmware os command injection vulnerabilityTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpR…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2025-12241), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.