PT-2025-30935 · Totolink · Totolink T6

·

CVE-2025-8170

·

Published

2025-07-25

·

Updated

2025-07-26

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK T6 version 4.1.5cu.748 B20211015
Description A critical vulnerability exists in the MQTT Packet Handler component of the affected product. The vulnerability is due to a buffer overflow in the tcpcheck net function within the /router/meshSlaveDlfw file. This issue can be exploited remotely by manipulating the serverIp argument. The exploit for this vulnerability has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10029
CVE-2025-8170

Affected Products

Totolink T6