← Vulnerability feed

Vulnerability record · CVE-2025-67187 · published 3 February 2026

CVE-2025-67187: Totolink a950rg firmware stack-based buffer overflow vulnerability

TTotolink · A950rg Firmware

A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists in the setIpQosRules interface of /lib/cste_modules/firewall.so where the comment parameter is not properly validated for length.

9.8 CVSS 3.1 Critical EPSS 0.47% · top 62.2% CWE-121 · Stack-based buffer overflow
9.8CVSS 3.1 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists in the setIpQosRules interface of /lib/cste_modules/firewall.so where the comment parameter is not properly validated for length.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-67187 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-67186Totolink a950rg firmware classic buffer overflow vulnerabilityTOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /lib/cste_modules/firewall.so.…EPSS 0.74%9.8CVE-2025-67188Totolink a950rg firmware classic buffer overflow vulnerabilityA buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg interface of the /lib/cste_mo…EPSS 0.65%9.8CVE-2025-44655Totolink a7100ru firmware vulnerabilityIn TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized acce…EPSS 0.34%9.8CVE-2025-45797Totolink a950rg firmware out-of-bounds write vulnerabilityTOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the …EPSS 17%9.8CVE-2025-45798Totolink a950rg firmware command injection vulnerabilityA command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface w…EPSS 1.2%9.8CVE-2025-45800Totolink a950rg firmware command injection vulnerabilityTOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so …EPSS 0.86%9.8CVE-2025-28035Totolink a830r firmware os command injection vulnerabilityTOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through th…EPSS 1.3%9.8CVE-2025-28036Totolink a950rg firmware os command injection vulnerabilityTOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through t…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2025-67187), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.