Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21986 | A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument telnet_enabled with the input 1 leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
Wed, 23 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink t6 Firmware
|
|
| CPEs | cpe:2.3:h:totolink:t6:3:*:*:*:*:*:*:* cpe:2.3:o:totolink:t6_firmware:v4.1.5cu.748_b20211015:*:*:*:*:*:*:* |
|
| Vendors & Products |
Totolink t6 Firmware
|
Tue, 22 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Jul 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument telnet_enabled with the input 1 leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | TOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authentication | |
| Weaknesses | CWE-287 CWE-306 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-07-22T14:14:27.289Z
Reserved: 2025-07-19T04:09:11.406Z
Link: CVE-2025-7862
Updated: 2025-07-22T14:14:14.656Z
Status : Analyzed
Published: 2025-07-20T03:15:23.773
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-7862
No data.
OpenCVE Enrichment
Updated: 2025-07-21T15:16:54Z
EUVD