Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-82616: TOTOLINK NR1800X router can be remotely crashed
CVE-2026-82616 · published 3 days ago
Summary
The router’s web interface has a flaw that lets an attacker send a specially crafted file name and overflow the memory stack. This can be triggered over the network, potentially causing the device to stop working or be taken over. Update the router firmware to the latest version or apply the vendor’s patch as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| totolink | nr1800x | 9.1.0u.6681_B20230703 |
Original advisory text
A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in...
A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
References
- https://vuldb.com/vuln/397117 vdb-entry technical-description
- https://vuldb.com/vuln/397117/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-82616 third-party-advisory
- https://vuldb.com/submit/892941 third-party-advisory
- https://github.com/lxiansheng488-bit/-/blob/main/TOTOlink/totolink%20setUploadSe... exploit
- https://www.totolink.net/ product
Severity
8.6
High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published31 Aug 2026
Updated1 Sep 2026
First seen31 Aug 2026
Monitor software like this
Free during beta