A buffer overflow vulnerability exists in the TOTOLINK...
Moderate severity
Unreviewed
Published
Nov 13, 2025
to the GitHub Advisory Database
•
Updated Nov 14, 2025
Description
Published by the National Vulnerability Database
Nov 13, 2025
Published to the GitHub Advisory Database
Nov 13, 2025
Last updated
Nov 14, 2025
A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the
global.sobinary. ThegetSaveConfigfunction retrieves thehttp_hostparameter from user input viawebsGetVarand copies it into a fixed-size stack buffer (v13) usingstrcpy()without performing any length checks. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted HTTP request to the router's web interface, potentially leading to arbitrary code execution.References