CVE-2026-79911: TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction. Exploitation involves manipulating the Hostname argument handled by the setSystemConfig function in /cgi-bin/cstecgi.cgi.
Which device version is identified as affected?
The reported affected version is TOTOLINK N600R 4.3.0cu.7647_B20210106. The provided information does not establish whether other firmware versions are affected.
How urgent is remediation?
This is rated critical with network attack vector, low attack complexity, no privileges required, and no user interaction required. Public exploit disclosure is reported, so exposed affected devices should be treated as high priority.