TOTOLINK A3300R Buffer Overflow Vulnerability in DDNS Configuration Function

Vulnerability

A buffer overflow vulnerability has been identified in the TOTOLINK A3300R router, specifically in the firmware version 17.0.0cu.557_B20221024. The issue arises in the 'setDdnsCfg' function within the file '/cgi-bin/cstecgi.cgi'. This vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability leads to a stack-based buffer overflow, which can commonly result in arbitrary code execution or causing the device to crash.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/cgi-bin/cstecgi.cgi' endpoint with a crafted 'provider' parameter. This parameter is not properly validated for length, allowing for an overflow when the 'provider' value is read back via the 'getDdnsCfg' function.

Added: Oct 27, 2025, 7:18 AM
Updated: Oct 27, 2025, 2:23 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.8
threat
6.4
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.