PT-2025-20420 · Totolink · Totolink A950Rg

Sunnyyangyaya

·

Published

2025-05-08

·

Updated

2025-05-08

·

CVE-2025-45797

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOlink A950RG version 4.1.2cu.5204 B20210112
Description The issue arises from improper input validation of the NoticeUrl parameter in the setNoticeCfg interface of the /lib/cste modules/system.so module. This leads to a buffer overflow.
Recommendations For TOTOlink A950RG version 4.1.2cu.5204 B20210112, consider restricting access to the setNoticeCfg interface in the /lib/cste modules/system.so module to minimize the risk of exploitation. Avoid using the NoticeUrl parameter in the affected interface until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-10011
CVE-2025-45797

Affected Products

Totolink A950Rg