CVE-2026-82616: TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow
A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
Which systems are known to be affected?
The affected product and version identified in the available data are TOTOLINK NR1800X running 9.1.0u.6681_B20230703. The vulnerable code is the setUploadSetting function in /cgi-bin/cstecgi.cgi.
What access does an attacker need to exploit this issue?
The attack can be executed remotely and requires low privileges. No user interaction is required.
How is the flaw triggered?
An attacker manipulates the FileName argument handled by setUploadSetting. This causes a stack-based buffer overflow.
Is exploit code available?
Yes. The available data states that a public exploit has been released and could be used.