- Affected Firmware: TOTOLINK_C8160R-1C_N600R_IP04291_8196D_SPI_4M32M_V4.3.0cu.7647_B20210106_ALL
- CVE-ID: CVE-2025-22900
- Root Cause: By analyzing the cstecgi.cgi file in the cgi-bin directory, I found that the function at address 0x420CD0 contains a stack overflow vulnerability.
- Impact: Remote unauthenticated attackers can execute arbitrary commands as root.
- Affected Firmware: TOTOLINK_C8160R-1C_N600R_IP04291_8196D_SPI_4M32M_V4.3.0cu.7647_B20210106_ALL
- CVE-ID: CVE-2025-22903
- Root Cause: By analyzing the cstecgi.cgi file in the cgi-bin directory, I found that the function at address 0x41CAF4 contains a stack overflow vulnerability.
- Impact: Remote unauthenticated attackers can execute arbitrary commands as root.
During my internship at Qi An Xin Tiangong Lab, I discovered a stack overflow vulnerability in the RE11S_1.11 router.
By analyzing the webs file in the bin directory, I found that the function formiNICbasicREP contains a stack overflow vulnerability.
The stack overflow can be triggered by the rootAPmac key value, which leads to a sprintf stack overflow.
During my internship at Qi An Xin Tiangong Lab, I discovered a stack overflow vulnerability in the Tenda-AC10 router.
By analyzing the webs file in the bin directory, I found that the function 0x45C380 contains a stack overflow vulnerability.
The stack overflow can be triggered by the mac2 key value, which leads to a strcpy stack overflow.
During my internship at Qi An Xin Tiangong Lab, I discovered a stack overflow vulnerability in the Tenda-AC10 router.
By analyzing the webs file in the bin directory, I found that the function 0x45C380 contains a stack overflow vulnerability.
The stack overflow can be triggered by the serverName2 key value, which leads to a strcpy stack overflow.
- Affected Firmware: US_AC10V4.0si_V16.03.10.20_cn_TDC01
- CVE-ID: CVE-2025-25454
- Root Cause: By analyzing the webs file in the bin directory, I found that the function 0x45C380 contains a stack overflow vulnerability.
- Impact: Remote unauthenticated attackers can execute arbitrary commands as root.
- Affected Firmware: US_AC10V4.0si_V16.03.10.20_cn_TDC01
- CVE-ID: CVE-2025-25455
- Root Cause: By analyzing the webs file in the bin directory, I found that the function 0x45C380 contains a stack overflow vulnerability.
- Impact: Remote unauthenticated attackers can hijack the program's control flow.
During my internship at Qi An Xin Tiangong Lab, I discovered a stack overflow vulnerability in the Tenda-AC10 router.
By analyzing the webs file in the bin directory, I found that the function 0x45C380 contains a stack overflow vulnerability.
The stack overflow can be triggered by the wanSpeed2 key value, which leads to a strcpy stack overflow.
- Affected Firmware: US_AC10V4.0si_V16.03.10.20_cn_TDC01
- CVE-ID: CVE-2025-25457
- Root Cause: By analyzing the webs file in the bin directory, I found that the function 0x45C380 contains a stack overflow vulnerability.
- Impact: Remote unauthenticated attackers can execute arbitrary commands as root.
- Affected Firmware: 240802
- CVE-ID: CVE-2025-29041
- Root Cause: By analyzing the webs file in the bin directory, I found that the function 0x41710c contains a command injection vulnerability.
- Impact: Remote unauthenticated attackers can execute arbitrary commands as root.

