Impact
A stack-based buffer overflow exists in the setRadvdCfg function of the ipv6.so component accessed via /cgi-bin/cstecgi.cgi. Manipulation of the radvdinterfacename argument can overflow the stack, enabling an attacker to execute arbitrary code. The flaw is exploitable remotely and the public exploit demonstrates practical use, meaning attackers can compromise device integrity and confidentiality. The weakness corresponds to CWE-119 and CWE-121, reflecting unsafe buffer handling and stack corruption.
Affected Systems
TOTOLINK A800R routers running firmware version 4.1.2cu.5137_B20200730 are affected. No other variants or versions were listed in the CNA data.
Risk and Exploitability
The vulnerability receives a CVSS score of 8.7, indicating high severity. EPSS data is not available, but the exploit is publicly available and listed in several advisory sites, suggesting a tangible threat. The flaw is not yet in the CISA KEV catalog. Attackers can trigger the overflow remotely via the web interface, potentially gaining control of the device without local access.
OpenCVE Enrichment