Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-79911Remote buffer overflow in TOTOLINK N600R

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

View on NVD

Analysis

El router TOTOLINK N600R presenta un desbordamiento de búfer en su manejador CGI que permite la ejecución remota de código al manipular el parámetro Hostname. Existe un exploit público disponible, lo que facilita ataques directos contra dispositivos vulnerables expuestos a la red. El impacto es crítico ya que permite el control total del hardware sin necesidad de autenticación previa.

Relevant roles

HardwareciberseguridadCLinux

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-119CWE-121

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Published: 8/25/2026, 11:17:59 PM
Last modified: 8/25/2026, 11:17:59 PM

References

HomeEventsBlogResourcesCoursesTeam