CVE-2026-31027: Buffer Overflow
TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cstemodules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary code execution or denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31027?
CVE-2026-31027 has a medium severity level due to the potential for remote exploitation via buffer overflow.
How do I fix CVE-2026-31027?
To fix CVE-2026-31027, update the TOTOlink A3600R firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-31027?
CVE-2026-31027 is a buffer overflow vulnerability that occurs in the setAppEasyWizardConfig interface.
Who is affected by CVE-2026-31027?
CVE-2026-31027 affects users running TOTOlink A3600R with firmware version 5.9c.4959.
Can CVE-2026-31027 be exploited remotely?
Yes, CVE-2026-31027 can be exploited remotely due to insufficient validation of the rootSsid parameter.