CVE-2025-3663
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Apr 16, 2025
Updated: May 12, 2025
CWE ID 284
CWE ID 266
Summary
CVE-2025-3663 is a critical vulnerability affecting the TOTOLINK A3700R and its software version 9.1.2u.5822_B20200513. This issue lies within the function setWiFiEasyCfg/setWiFiEasyGuestCfg in the Password Handler's /cgi-bin/cstecgi.cgi file. The manipulation results in inadequate access controls, potentially enabling remote attacks. The vulnerability has been publicly disclosed, increasing the risk of exploitation. Despite early notifications, the vendor has not responded to address the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- TOTOLINK