Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-82616: TOTOLINK NR1800X router can be remotely crashed

CVE-2026-82616 · published 3 days ago
Summary

The router’s web interface has a flaw that lets an attacker send a specially crafted file name and overflow the memory stack. This can be triggered over the network, potentially causing the device to stop working or be taken over. Update the router firmware to the latest version or apply the vendor’s patch as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
totolink nr1800x 9.1.0u.6681_B20230703
Original advisory text
A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in...
A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
Severity
8.6 High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published31 Aug 2026
Updated1 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-82616 · MITRE
Monitor software like this
Free during beta