Impact
A stack‑based buffer overflow exists in the setIpQosRules function of the firewall.so component, triggered by an excessively long Comment argument in /cgi-bin/cstecgi.cgi. The flaw can be exploited remotely, allowing an attacker to overwrite the stack and execute arbitrary code on the device, compromising confidentiality, integrity, and availability of the network appliance. The weakness is classified as CWE‑119 and CWE‑121.
Affected Systems
The vulnerability affects TOTOLINK A800R routers running firmware version 4.1.2cu.5137_B20200730. Only this specific firmware build is known to be vulnerable; other revisions are not known to be impacted.
Risk and Exploitability
With a CVSS score of 8.7 the flaw is considered high severity. The EPSS score is not available, but the exploit has been released publicly and may be used for attacks. Although the vulnerability is not listed in CISA KEV, its remote exploitation capability and available exploit code indicate a significant risk of compromise in exposed or poorly secured environments.
OpenCVE Enrichment