TOTOLINK T6
cpe:2.3:h:totolink:t6:*:*:*:*:*:*:*, +1 more
- <= 4.1.5cu.748_B20211015
A critical buffer overflow vulnerability has been identified in the TOTOLINK T6 router, specifically in versions up to 4.1.5cu.748_B20211015. The issue arises in the HTTP POST request handler, within the 'setDiagnosisCfg' function of the '/cgi-bin/cstecgi.cgi' file. The vulnerability can be exploited remotely by manipulating the 'ip' argument, leading to potential unauthorized memory access or code execution.
Exploitation of this vulnerability causes a buffer overflow, which can commonly lead to arbitrary code execution or causing the device to crash.
The vulnerability can be reproduced by sending a malicious HTTP POST request to the '/cgi-bin/cstecgi.cgi' endpoint, with the 'ip' argument crafted to trigger the buffer overflow. This can be done using various tools that allow for the manipulation of HTTP request data, such as curl or Postman.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.