Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-79911Desbordamiento de búfer remoto en TOTOLINK N600R

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Ver en NVD

Análisis

El router TOTOLINK N600R presenta un desbordamiento de búfer en su manejador CGI que permite la ejecución remota de código al manipular el parámetro Hostname. Existe un exploit público disponible, lo que facilita ataques directos contra dispositivos vulnerables expuestos a la red. El impacto es crítico ya que permite el control total del hardware sin necesidad de autenticación previa.

Roles relevantes

HardwareciberseguridadCLinux

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-119CWE-121

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Publicada: 25/8/2026, 23:17:59
Última modificación: 25/8/2026, 23:17:59

Referencias

InicioEventosBlogRecursosCursosEquipo