Impact
A null pointer dereference can be triggered by sending specially crafted HTTP requests to the cstecgi.cgi handler in TOTOLINK WA1200 firmware 5.9c.2914. This flaw causes the HTTP service to crash, resulting in a loss of ability to manage or access the router. The weakness is a null dereference (CWE‑476) and poses a denial‑of‑service risk to all users of the device.
Affected Systems
The flaw affects TOTOLINK WA1200 routers running firmware 5.9c.2914. No other vendor or version information is given, and the vulnerability is associated with the device model WA1200‑POE used by TOTOLINK.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. The EPSS score is inferred to be less than 1 percent, signalling a low likelihood of exploitation at present. The vulnerability has not been included in the CISA KEV catalog. Because the flaw is triggered via an HTTP request, the attack vector is network‑based and the attacker only needs remote access to the web interface of the router.
OpenCVE Enrichment