Impact
The vulnerability is a stack-based buffer overflow in the setWiFiWpsConfig function of the wps.so component in the TOTOLINK A800R. Manipulating the pin argument can overflow a local buffer, potentially allowing an attacker to execute arbitrary code or crash the system, leading to confidentiality, integrity, or availability compromise. The flaw aligns with CWE-119 and CWE-121 weaknesses.
Affected Systems
The issue affects the TOTOLINK A800R router running firmware version 4.1.2cu.5137_B20200730. No other firmware releases are documented as vulnerable at this time.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the absence of an EPSS score suggests insufficient data on exploitation frequency but the public release of an exploit and the remote attackability raise concern. The vulnerability is not yet listed in CISA KEV. Because the attack can be launched remotely, the risk to systems exposed to the internet or WiFi networks is significant, and mitigations should be prioritized.
OpenCVE Enrichment