CVE-2026-1686: Totolink A3600R app.so setAppEasyWizardConfig buffer overflow
A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig in the library /lib/cstemodules/app.so. Performing a manipulation of the argument apcliSsid results in buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1686?
CVE-2026-1686 is classified as a high severity vulnerability due to the buffer overflow allowing potential remote code execution.
How do I fix CVE-2026-1686?
To fix CVE-2026-1686, you should update the Totolink A3600R firmware to the latest version that addresses this issue.
What impact does CVE-2026-1686 have on my device?
CVE-2026-1686 can lead to unauthorized access and execution of arbitrary code on the affected Totolink A3600R device.
Who is affected by CVE-2026-1686?
CVE-2026-1686 affects users of the Totolink A3600R router running firmware version 5.9c.4959.
What are the symptoms of CVE-2026-1686 exploitation?
Exploitation of CVE-2026-1686 may result in abnormal device behavior, unexpected reboots, or complete loss of control of the router.