Impact
The vulnerability arises in TOTOLINK EX1200L firmware 9.3.5u.6146_B20201023 within the setWizardCfg function of /cgi-bin/cstecgi.cgi. An attacker can remotely supply crafted input that triggers a null pointer dereference, causing the web service or device to crash. This loss of service impact is reflected in the CVSS score of 7.1 and is classified under CWEs for null pointer dereference (CWE-476) and CWE-404.
Affected Systems
Affected devices are TOTOLINK EX1200L units running firmware version 9.3.5u.6146_B20201023. No other versions or models are explicitly listed as impacted, so the risk is confined to this specific build.
Risk and Exploitability
The CVSS score indicates high severity availability risk. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog. Attackers can launch the exploit remotely by targeting the CGI endpoint. Because the exploit has been made public, the likelihood of exploitation is elevated for networks where the device is exposed to untrusted traffic.
OpenCVE Enrichment