Impact
The vulnerability involves a stack-based buffer overflow in the setUploadSetting function of /cgi-bin/cstecgi.cgi on the TOTOLINK NR1800X router. By manipulating the FileName argument, an attacker can overflow the stack and potentially execute arbitrary code on the device. This flaw can be triggered remotely, giving an attacker the ability to gain control of the router without local access. The impact hence includes full system compromise, data theft, and the ability to use the device in a botnet.
Affected Systems
This flaw affects the TOTOLINK NR1800X model running firmware version 9.1.0u.6681_B20230703. No other models or firmware revisions were listed as vulnerable in the current data. Attackers should verify whether their device matches this exact firmware revision.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity, and the EPSS score is not available, making it unclear how frequently the vulnerability is exploited in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation via the vulnerable CGI endpoint, which can be accessed over the network without authentication. If the router exposes the necessary port to the Internet, the attacker can trigger the overflow and execute arbitrary code.
OpenCVE Enrichment