Impact
A flaw in the Password Configuration Handler of the TOTOLINK EX1200L router, specifically within the setPasswordCfg function of the /cgi-bin/cstecgi.cgi CGI script, permits a crafted request to cause a null pointer dereference. The function executes during password configuration and the dereference results in a crash of the CGI process. The vulnerability allows remote initiation and can destabilize the router. The weakness is identified as a null pointer dereference (CWE-476) and unsupported operation (CWE-404). No explicit evidence of code execution is provided, but the crash could interrupt critical services and, depending on the underlying operating system, could potentially expose further vulnerabilities.
Affected Systems
The vulnerability affects the TOTOLINK EX1200L router running firmware version 9.3.5u.6146_B20201023. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates that a successful exploit would have a high impact and a significant likelihood of exploitation. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker can initiate the exploit remotely by sending a specially crafted request to the /cgi-bin/cstecgi.cgi endpoint. This can trigger repeated crashes of the CGI process, resulting in denial of service. While the description does not confirm that memory corruption or undefined behavior can be harnessed for code execution, the risk of serious disruption is clear.
OpenCVE Enrichment