CVE-2025-67189: Buffer Overflow
A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204B20210112. The urlKeyword parameter is not properly validated, and the function concatenates multiple user-controlled fields into a fixed-size stack buffer without performing boundary checks. A remote attacker can exploit this flaw to cause denial of service or potentially achieve arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67189?
CVE-2025-67189 has a high severity rating due to the potential for remote code execution through a buffer overflow.
How do I fix CVE-2025-67189?
To fix CVE-2025-67189, upgrade your TOTOLINK A950RG device to the latest firmware that addresses the buffer overflow vulnerability.
What are the potential impacts of CVE-2025-67189?
The potential impacts of CVE-2025-67189 include unauthorized access, system crashes, and execution of arbitrary code on affected devices.
Who is affected by CVE-2025-67189?
Users of TOTOLINK A950RG with firmware version 4.1.2cu.5204_B20210112 are affected by CVE-2025-67189.
Are there any workarounds for CVE-2025-67189?
Currently, the best workaround for CVE-2025-67189 is to disable the setParentalRules interface until a patch is applied.