A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument apcliSsid results in buffer overflow.
The attack can be executed remotely. The exploit is now public and may be used.
Attack Parameters
Impact Assessment
CVSS Vector v4.0