Impact
The vulnerability originates from an unchecked buffer copy in the setWiFiBasicCfg function of /cgi-bin/cstecgi.cgi. An attacker can supply a malformed ssid argument that overflows a buffer, enabling arbitrary code execution on the device. The flaw is a classic buffer overflow (CWE‑119 and CWE‑120), allowing compromise of the router’s confidentiality, integrity, and availability.
Affected Systems
The flaw affects Totolink LR350 routers with firmware 9.3.5u.6369_B20220309. The specific asset is the cstecgi.cgi CGI script that handles wireless configuration through the web interface. Devices running this firmware version are vulnerable when exposed to the internet or to the local network.
Risk and Exploitability
CVSS score 8.7 indicates a high severity. The EPSS is below 1%, suggesting that the threat may not be widely exploited at present, and the vulnerability is not listed in the CISA KEV catalogue. Nevertheless, because the attack vector is remote and the flaw can be triggered via a standard Web request, the risk remains significant. An attacker who succeeds can execute code on the device and potentially take control of the network.
OpenCVE Enrichment