Executive brief
A security vulnerability exists in several TOTOLINK networking devices, including routers and range extenders. An attacker could exploit this flaw to bypass intended security restrictions and gain unauthorized access or elevated privileges on the device. This could lead to full control over the network traffic passing through the device or unauthorized changes to network settings.
Technical details
This vulnerability is classified as an incorrect privilege assignment (CWE-266) and least privilege violation (CWE-272) within the Web Interface of multiple TOTOLINK devices. The flaw is specifically associated with the handling of the /etc/boa/boa.conf configuration file. A remote attacker with low privileges can exploit this vulnerability to gain higher-level access. While the attack can be initiated over the network, it is characterized by high complexity and is considered difficult to exploit in practice. Successful exploitation allows for a complete compromise of confidentiality, integrity, and availability on the affected hardware.
Affected products
- TOTOLINK A3000RU up to 20260906
- TOTOLINK A3100R up to 20260906
- TOTOLINK A950RG up to 20260906
- TOTOLINK AC1200T10 up to 20260906
- TOTOLINK CP450 up to 20260906
- TOTOLINK CS185R_T10 up to 20260906
- TOTOLINK EX200 up to 20260906
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory