CVE-2025-67189

A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The urlKeyword parameter is not properly validated, and the function concatenates multiple user-controlled fields into a fixed-size stack buffer without performing boundary checks. A remote attacker can exploit this flaw to cause denial of service or potentially achieve arbitrary code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5204_b20210112:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:*

History

17 Jun 2026, 09:57

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de desbordamiento de búfer en la interfaz setParentalRules de TOTOLINK A950RG V4.1.2cu.5204_B20210112. El parámetro urlKeyword no se valida correctamente, y la función concatena múltiples campos controlados por el usuario en un búfer de pila de tamaño fijo sin realizar comprobaciones de límites. Un atacante remoto puede explotar esta falla para causar denegación de servicio o potencialmente lograr ejecución de código arbitrario.

10 Feb 2026, 14:15

Type Values Removed Values Added
First Time Totolink a950rg Firmware
Totolink a950rg
Totolink
CPE cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5204_b20210112:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:*
References () https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A950RG/5024-setParentRules-urlKeyWord-buffer.md - () https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A950RG/5024-setParentRules-urlKeyWord-buffer.md - Exploit, Third Party Advisory

09 Feb 2026, 22:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 6.5

05 Feb 2026, 15:16

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

03 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 18:16

Updated : 2026-06-17 09:57


NVD link : CVE-2025-67189

Mitre link : CVE-2025-67189

CVE.ORG link : CVE-2025-67189


JSON object : View

Products Affected

totolink

  • a950rg
  • a950rg_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')