Impact
The vulnerability is a stack‑based buffer overflow in the setParentalRules function of the firewall.so component exposed through /cgi-bin/cstecgi.cgi. A crafted urlKeyword argument can overflow the stack and allow arbitrary code execution, enabling complete compromise of the device. The flaw belongs to CWE‑119 and CWE‑121 and carries a CVSS score of 8.7.
Affected Systems
TOTOLINK A800R routers running firmware version 4.1.2cu.5137_B20200730 (and any earlier builds that contain the same firewall.so implementation). The flaw is triggered by the cstecgi.cgi CGI script used to configure parental rules.
Risk and Exploitability
The CVSS score indicates a high severity risk. Although no EPSS score is published and the vulnerability has not yet been listed in the CISA KEV catalog, publicly available exploits demonstrate that an attacker can remotely trigger the overflow by sending a malformed urlKeyword value. This allows full control over the affected device, posing severe threats to confidentiality, integrity, and availability.
OpenCVE Enrichment