CVE-2025-67187: Buffer Overflow
A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204B20210112. The flaw exists in the setIpQosRules interface of /lib/cstemodules/firewall.so where the comment parameter is not properly validated for length.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67187?
CVE-2025-67187 is classified as a high-severity stack-based buffer overflow vulnerability.
How do I fix CVE-2025-67187?
To fix CVE-2025-67187, update the TOTOLINK A950RG to the latest firmware version that addresses this vulnerability.
What are the potential impacts of CVE-2025-67187?
The potential impacts of CVE-2025-67187 include unauthorized code execution and system instability due to buffer overflow.
Is the TOTOLINK A950RG affected by CVE-2025-67187?
Yes, the TOTOLINK A950RG version 4.1.2cu.5204_B20210112 is affected by CVE-2025-67187.
What component of the TOTOLINK A950RG is vulnerable in CVE-2025-67187?
The vulnerable component in CVE-2025-67187 is the setIpQosRules interface in the /lib/cste_modules/firewall.so.