CNNVD-202602-350 Information

CNNVD ID

CNNVD-202602-350

CVE-2025-67186

  • CNNVD Published: 2026-02-03

Description (Chinese)

TOTOLINK A950RG是中国吉翁电子(TOTOLINK)公司的一款超世代 Giga 无线路由器。 TOTOLINK A950RG V4.1.2cu.5204_B20210112版本存在安全漏洞,该漏洞源于setUrlFilterRules接口对url参数长度验证不足,可能导致缓冲区溢出、执行任意代码或拒绝服务。

Description (English)

TOTOLINK A950RG is a multigenerational Giga Wireless router of the Chinese company TOTOLINK. TOTOLINK A950RG V4.1.2cu.5204 B20101112 contains a security loophole, which stems from the inadequate verification of the length of the url parameters on the seturilFilter Rules interface, which may lead to the spilling out of the buffer zone, the enforcement of arbitrary codes or the denial of services.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

吉翁电子

Published

2026-02-03

Last Modified

2026-02-24

References

https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A950RG/5024-setUrlFliterRules-url-buffer.md

Share on: