CVE-2026-79912: TOTOLINK N600R cstecgi.cgi getCurrentTime command injection
Published Aug 25, 2026
·Updated
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntpserver results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
1 affected component
TOTOLINK N600R=4.3.0cu.7647_B20210106
Event History
Aug 25, 2026
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires manipulation of the ntp_server argument supplied to the getCurrentTime function in /cgi-bin/cstecgi.cgi. The provided severity vector indicates no privileges or user interaction are required.
2
Is public exploit code available?
Yes. The vulnerability information states that an exploit is public and may be used.
3
Which device version is identified as affected?
The reported affected version is TOTOLINK N600R 4.3.0cu.7647_B20210106.