Impact
A flaw in the setMacFilterRules function of the cstecgi.cgi file on TOTOLINK A720R routers permits an attacker to manipulate the desc argument, resulting in a buffer overflow that can corrupt memory. The data corruption may allow execution of arbitrary code or similar impact on the router’s integrity, confidentiality and availability. The vulnerability is classified as a memory corruption weakness identified by CWE-119.
Affected Systems
The affected product is the TOTOLINK A720R router running firmware version 4.1.5cu.630_B20250509. No other versions are listed as affected, but the vulnerability applies to all routers running this firmware revision.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the vulnerability has been publicly disclosed and can be exploited remotely. It is not currently listed in the CISA KEV catalog. The attack vector is remote, relying on sending crafted requests to the router’s web interface to trigger the overflow.
OpenCVE Enrichment