CVE-2025-3664

CVSS 2.0 Score 5 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 22, 2025
CWE ID 284
CWE ID 266

Summary

CVE-2025-3664 is a critical vulnerability identified in the TOTOLINK A3700R 9.1.2u.5820_B20200513 firmware. The issue lies within the setWiFiEasyGuestCfg function of the /cgi-bin/cstecgi.cgi file, resulting in improper access controls. An attacker can exploit this remotely, gaining unauthorized access. Although the vulnerability was reported to the vendor, they have yet to respond or provide a patch. Public disclosure of the exploit increases the risk of attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share