CVE-2026-79911
Deferred Deferred - Pending Action

Stack-Based Buffer Overflow in TOTOLINK N600R Router

Vulnerability report for CVE-2026-79911, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-27

Assigner: VulDB

Description

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-27
Generated
2026-09-15
AI Q&A
2026-08-26
EPSS Evaluated
2026-09-13
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
totolink n600r 4.3.0cu.7647_b20210106

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stack-based buffer overflow in TOTOLINK N600R 4.3.0cu.7647_B20210106. It occurs in the setSystemConfig function of the file /cgi-bin/cstecgi.cgi when the Hostname argument is manipulated. This allows remote attackers to execute arbitrary code by sending specially crafted input.

Detection Guidance

Detecting this vulnerability requires checking for vulnerable TOTOLINK N600R devices with firmware version 4.3.0cu.7647_B20210106. Scan your network for devices running this firmware and inspect CGI handler endpoints for the /cgi-bin/cstecgi.cgi path. Look for unusual traffic patterns targeting the Hostname parameter in setSystemConfig.

Impact Analysis

This vulnerability allows remote attackers to execute arbitrary code on the affected device. This could lead to unauthorized access, data theft, or disruption of network services. Since the exploit is publicly available, the risk of exploitation is high.

Compliance Impact

The vulnerability allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the TOTOLINK N600R device. This could lead to unauthorized access, data exfiltration, or system compromise, which may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) if exploited.

Mitigation Strategies

Immediately update the TOTOLINK N600R firmware to the latest version to patch the stack-based buffer overflow vulnerability in the setSystemConfig function. Disable remote access to the CGI handler at /cgi-bin/cstecgi.cgi if not required. Monitor network traffic for unusual activity targeting this endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79911. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart