TOTOLINK A810R
cpe:2.3:h:totolink:a810r:*:*:*:*:*:*:*, +1 more
- V4.1.2cu.5182_B20201026
A buffer overflow vulnerability has been identified in the TOTOLINK A810R router, specifically in the firmware version V4.1.2cu.5182_B20201026. The issue arises in the downloadFile.cgi file, where user-supplied input is not properly validated before being copied into a buffer, allowing for potential memory corruption.
Exploitation of this vulnerability leads to a buffer overflow condition, which can commonly result in arbitrary code execution or causing the device to crash.
To reproduce this vulnerability, send a request to the downloadFile.cgi endpoint with a payload that includes the v14 parameter. The v5 parameter must contain data that exceeds 132 bytes, which will trigger the buffer overflow by overwriting adjacent memory.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.