Impact
A buffer overflow occurs in the setWizardCfg function of the Totolink NR1800X firmware when the ssid parameter is supplied in a POST request. The vulnerability satisfies CWE-119 and CWE-120, enabling an attacker to corrupt memory and potentially execute arbitrary code. If successfully exploited, an attacker could gain remote control over the device, compromise network traffic, or disrupt service availability.
Affected Systems
The affected device is the Totolink NR1800X router running firmware version 9.1.0u.6279_B20210910. The flaw resides in the cstecgi.cgi component of the POST request handler.
Risk and Exploitability
The CVSS score of 8.7 classifies this as high severity, yet the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the public exploit is available and can be triggered remotely by sending a crafted POST request to the setWizardCfg endpoint.
OpenCVE Enrichment