---
id: CVE-2025-11444
title: >-
  A security vulnerability has been detected in TOTOLINK N600R up to
  4.3.0cu.7866_B20220506
summary: >-
  A security vulnerability has been detected in TOTOLINK N600R up to
  4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the
  file /cgi-bin/cstecgi.cgi of the component HTTP Request Handler. Such
  manipulation of the argu…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: totolink
product: n600r_firmware
affected:
  - n600r_firmware <= 4.3.0cu.7866_b2022506
published: '2025-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11444'
references:
  - url: >-
      https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/TOTOLINK/wepkey/wepkey.md
    label: cna@vuldb.com
  - url: >-
      https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/TOTOLINK/wepkey/wepkey.md#reproduce
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327381'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327381'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.666915'
    label: cna@vuldb.com
  - url: 'https://www.totolink.net/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/TOTOLINK/wepkey/wepkey.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/TOTOLINK/wepkey/wepkey.md#reproduce
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0104
epssPercentile: 0.62894
ingestedAt: '2026-10-08T13:42:55.000Z'
---

## Overview

A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the component HTTP Request Handler. Such manipulation of the argument wepkey leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

## Affected

- `n600r_firmware <= 4.3.0cu.7866_b2022506`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
