TOTOLINK A950RG Buffer Overflow Vulnerability in URL Filter Rules Interface Allowing Arbitrary Code Execution or Denial-of-Service

Vulnerability

A buffer overflow vulnerability has been identified in the TOTOLINK A950RG router, specifically in firmware version V4.1.2cu.5204_B20210112. The issue arises in the 'setUrlFilterRules' interface of '/lib/cste_modules/firewall.so', where the 'url' parameter is inadequately validated for length. This flaw enables remote attackers to exploit the buffer overflow, potentially leading to arbitrary code execution or a denial-of-service condition.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition or allow for arbitrary code execution on the device.

Reproduction

The vulnerability can be reproduced by sending a POST request to '/cgi-bin/cstecgi.cgi' with a crafted 'url' parameter that exceeds the buffer's length limit. This can be done using a web application that allows for the manipulation of HTTP request parameters, such as a custom script or a tool like Postman.

Added: Feb 3, 2026, 6:40 PM
Updated: Feb 3, 2026, 6:40 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
7.5
exploitability
9.1
remediation
0.0
relevance
2.5
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.