Impact
The vulnerability is a stack-based buffer overflow in TOTOLINK A800R firmware 4.1.2cu.5137_B20200730. By manipulating the url argument supplied to the setUrlFilterRules function in /cgi-bin/cstecgi.cgi, an attacker can corrupt the stack and execute arbitrary code remotely. The overflow can lead to complete compromise of the device, enabling an attacker to gain full control, read or modify configuration, or disrupt network services.
Affected Systems
The affected product is the TOTOLINK A800R router running firmware version 4.1.2cu.5137_B20200730. No other firmware revisions are listed as vulnerable in the CNA data.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability and the publicly available exploit demonstrates that remote attackers can exploit the flaw from outside the local network. Although the EPSS score not reported, the presence of a known exploit suggests a non‑negligible likelihood of real‑world attacks. The vulnerability is not yet catalogued in CISA KEV, but its impact is severe and the attack vector is remote via the web interface.
OpenCVE Enrichment