CVE-2026-82555
Received Received - Intake

Insufficiently Random Values in TOTOLINK N600R Authentication

Vulnerability report for CVE-2026-82555, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: VulDB

Description

A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insufficiently random values. It is possible to launch the attack remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
totolink n600r 4.3.0cu.7866_b20220506
totolink n600r 4.3.0cu.7866

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-310 Cryptographic Issues
CWE-330 The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-82555 is a vulnerability in TOTOLINK N600R router firmware V4.3.0cu.7866_B20220506. It involves a predictable session token generation mechanism where the cookie_key is derived from an MD5 hash of the current Unix timestamp. This allows attackers to brute-force valid session tokens and hijack admin sessions.

Detection Guidance

To detect this vulnerability, monitor network traffic for predictable session tokens generated via MD5 hashes of Unix timestamps. Check for repeated login attempts to /web_cste/cgi-bin/cstecgi.cgi with cookie_key values derived from timestamps. Use tools like Wireshark to inspect HTTP requests for session token patterns.

Impact Analysis

An attacker could exploit this to gain full control of the router, read sensitive information like Wi-Fi passwords and PPPoE credentials, modify settings such as DNS and firewall rules, or even flash new firmware causing a denial of service.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA due to its impact on data confidentiality and integrity. The predictable session tokens allow unauthorized access to sensitive router settings and credentials, which may include personal or protected health information if transmitted or stored on the device. Unauthorized access to such data could lead to breaches of confidentiality requirements under these regulations.

Mitigation Strategies

Immediately update the TOTOLINK N600R firmware to the latest version. Disable remote administration access if not required. Implement network segmentation to isolate the router from critical systems. Monitor for unauthorized access attempts or unusual administrative activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82555. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart