Impact
A flaw in the web interface component that manages the /etc/boa/boa.conf file allows an attacker to alter configuration settings and bypass the router’s least‑privilege model, effectively granting higher privileges and control over the device. The vulnerability is identified as CWE-266 (Improper Restriction of Component Permissions) and CWE-272 (Least Privilege Violation). The attack can be launched remotely through the router’s web management interface.
Affected Systems
Affected TOTOLINK routers include models A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 running firmware up to version 20260906; all devices with those models and firmware versions are potentially vulnerable.
Risk and Exploitability
The vulnerability has a CVSS severity score of 7.7, marking it as high. Its EPSS score is less than 1 percent, and it is not listed in the CISA KEV catalog. The attack vector is external via the web interface, but the exploit complexity is rated high and no public exploit is documented, indicating a moderate‑to‑high overall risk that warrants timely remediation.
OpenCVE Enrichment