Impact
A stack-based buffer overflow exists in the UploadCustomModule function of /cgi-bin/cstecgi.cgi within the product.so component of TOTOLINK A800R firmware 4.1.2cu.5137_B20200730. By manipulating the File argument, an attacker can overwrite stack data and potentially hijack execution flow, allowing arbitrary code execution, and compromising confidentiality, integrity, and availability of the device.
Affected Systems
The vulnerability affects TOTOLINK A800R routers running firmware version 4.1.2cu.5137_B20200730. The product is the product.so library bundled in the router’s firmware.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity. The EPSS score is not available, yet the vulnerability has an openly published exploit, indicating that exploitation is feasible. The attack can be launched remotely by sending crafted requests to the /cgi-bin/cstecgi.cgi endpoint. Although the vulnerability is not yet listed in the CISA KEV catalog, the presence of a public exploit and the ease of remote access raise the likelihood that attackers may target vulnerable devices within close network proximity.
OpenCVE Enrichment