Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-79911: TOTOLINK N600R router can be remotely compromised via hostname

CVE-2026-79911 · published 9 days ago
Summary

The router’s web interface has a flaw that lets an attacker send a specially crafted hostname and cause the system to overflow its memory. This can be triggered from anywhere on the internet, potentially giving the attacker control of the device. Update the router firmware to the latest version or apply the vendor’s patch as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
totolink n600r 4.3.0cu.7647_B20210106
Original advisory text
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handl...
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Severity
9.3 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published25 Aug 2026
Updated3 Sep 2026
First seen25 Aug 2026
Sources
CVE-2026-79911 · MITRE
Monitor software like this
Free during beta