Description
A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument apcliSsid results in buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-04-12: | Advisory disclosed |
| 2026-04-12: | VulDB entry created |
| 2026-04-12: | VulDB entry last update |
Credits
xuanyu (VulDB User)
References
vuldb.com/vuln/357037 (VDB-357037 | Totolink A800R app.so setAppEasyWizardConfig buffer overflow)
vuldb.com/vuln/357037/cti (VDB-357037 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/793114 (Submit #793114 | TOTOLINK A800R V4.1.2cu.5137_B20200730 Buffer Overflow)
github.com/...R/01_Buffer_Overflow_setAppEasyWizardConfig.md
www.totolink.net/