Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-79911: TOTOLINK N600R router can be remotely compromised via hostname
CVE-2026-79911 · published 9 days ago
Summary
The router’s web interface has a flaw that lets an attacker send a specially crafted hostname and cause the system to overflow its memory. This can be triggered from anywhere on the internet, potentially giving the attacker control of the device. Update the router firmware to the latest version or apply the vendor’s patch as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| totolink | n600r | 4.3.0cu.7647_B20210106 |
Original advisory text
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handl...
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
References
- https://vuldb.com/vuln/395061 vdb-entry technical-description
- https://vuldb.com/vuln/395061/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-79911 third-party-advisory
- https://vuldb.com/submit/881258 third-party-advisory
- https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/... exploit
- https://www.totolink.net/ product
Severity
9.3
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published25 Aug 2026
Updated3 Sep 2026
First seen25 Aug 2026
Monitor software like this
Free during beta