Impact
A stack-based buffer overflow was found in TOTOLINK A800R firmware version 4.1.2cu.5137_B20200730. The vulnerability is triggered by manipulating the Comment parameter in the cstecgi.cgi component, allowing an attacker to overflow the stack and potentially execute arbitrary code from a remote location.
Affected Systems
The affected product is the TOTOLINK A800R router running firmware 4.1.2cu.5137_B20200730. No other versions or products are currently listed as vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity. EPSS information is not available, and the vulnerability is not listed in CISA's KEV catalog, but the exploit has been publicly disclosed and can be launched remotely, making it likely that attackers could target vulnerable devices if they are reachable from the internet.
OpenCVE Enrichment