CVE-2026-1328: Totolink NR1800X POST Request cstecgi.cgi setWizardCfg buffer overflow
A vulnerability was detected in Totolink NR1800X 9.1.0u.6279B20210910. Impacted is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1328?
CVE-2026-1328 is considered a critical vulnerability due to the potential for buffer overflow.
How do I fix CVE-2026-1328?
To fix CVE-2026-1328, update your Totolink NR1800X to the latest firmware version provided by the vendor.
What types of attacks can exploit CVE-2026-1328?
CVE-2026-1328 can be exploited through specially crafted POST requests targeting the setWizardCfg function.
Which devices are affected by CVE-2026-1328?
The Totolink NR1800X model running firmware version 9.1.0u.6279_B20210910 is affected by CVE-2026-1328.
What are the potential impacts of CVE-2026-1328?
CVE-2026-1328 may lead to remote code execution, allowing attackers to gain unauthorized access to the device.