CVE-2025-67186: Buffer Overflow
TOTOLINK A950RG V4.1.2cu.5204B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /lib/cstemodules/firewall.so. The vulnerability occurs because the url parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary code execution or denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67186?
CVE-2025-67186 is classified as a high-severity vulnerability due to its potential to allow remote attackers to exploit a buffer overflow.
How does CVE-2025-67186 affect the TOTOLINK A950RG router?
CVE-2025-67186 affects the TOTOLINK A950RG router by allowing remote attackers to trigger a buffer overflow via the setUrlFilterRules interface.
How do I fix CVE-2025-67186 on my TOTOLINK A950RG device?
To fix CVE-2025-67186, ensure that your TOTOLINK A950RG router firmware is updated to a version that addresses the buffer overflow issue.
What is the impact of CVE-2025-67186 if exploited?
If exploited, CVE-2025-67186 can lead to unauthorized access, potential execution of arbitrary code, and compromise of the affected device.
Are there any known exploits for CVE-2025-67186?
As of now, specific exploit code for CVE-2025-67186 may exist, increasing the urgency for patching the vulnerability to protect against potential attacks.