Impact
A stack‑based buffer overflow exists in the setMacFilterRules function of /cgi-bin/cstecgi.cgi on the TOTOLINK A800R. The vulnerability is triggered by manipulating the Comment argument, causing a stack corruption that can lead to arbitrary code execution. The weakness is classified as CWE-119 and CWE-121.
Affected Systems
The affected product is the TOTOLINK A800R model with firmware version 4.1.2cu.5137_B20200730. The vulnerability lies in the firewall.so component and the setMacFilterRules endpoint exposed via the web interface.
Risk and Exploitability
The CVSS score is 8.7, indicating high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The description states that the attack can be performed from remote, and a public exploit has already been disclosed. This combination of remote attack vector, public exploit, and high severity makes the risk significant for deployments that allow remote management of the device.
OpenCVE Enrichment