CVE-2025-3668

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 16, 2025
Updated: May 12, 2025
CWE ID 284
CWE ID 266

Summary

CVE-2025-3668 is a critical vulnerability affecting the TOTOLINK A3700R with firmware version 9.1.2u.5822_B20200513. The issue lies within the function setScheduleCfg in the file /cgi-bin/cstecgi.cgi, resulting in improper access controls. This flaw allows remote attackers to manipulate the system, posing a significant security risk. Regrettably, the vulnerability has been disclosed to the public, increasing the likelihood of exploitation. Despite early notifications to the vendor, they have yet to respond or provide a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share