Impact
A stack-based buffer overflow exists in the setMacQos function of the firewall.so component on the TOTOLINK A800R, where manipulating the macAddress argument can corrupt the stack and potentially allow an attacker to execute arbitrary code. The flaw is a classic instance of unchecked input leading to memory corruption, identified as CWE-119 and CWE-121. The vulnerability, when exploited, enables remote attackers to override control data on the stack, leading to full system compromise (privilege escalation, arbitrary code execution, or denial of service). The CVE description confirms the attack can be initiated remotely and that a public exploit is available.
Affected Systems
The vulnerability is present in TOTOLINK A800R routers running firmware 4.1.2cu.5137_B20200730. No other product versions or variants are listed as affected in the available data.
Risk and Exploitability
With a CVSS score of 8.7, this flaw is classified as high severity. Although the EPSS score is not provided, the advisories indicate that the exploit is publicly available, implying a realistic likelihood of compromise for exposed devices that have not been patched. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, but its remote trigger and stack corruption potential make it a critical risk for any device reachable from untrusted networks.
OpenCVE Enrichment