Description
Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as bricking the router.

Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146_B20201023 but may also affect other versions.
Published: 2026-06-23
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic stack‑based buffer overflow in the login functionality exposed through the cgi-bin/cstecgi.cgi endpoint of the Totolink EX1200L router. By sending a crafted request an attacker can cause the program to crash and gain arbitrary code execution. The remote execution privilege is that of the router’s root user, enabling full control over the device, including reading, modifying, and deleting configuration data or rendering the device inoperable. The high CVSS score of 9.4 reflects the severity and the potential for system‑wide compromise.

Affected Systems

The flaw has been confirmed in firmware build 9.3.5u.6146_B20201023 of the Totolink EX1200L model. Vendor contact attempts were unsuccessful and no other firmware revisions have been verified, but the problem likely affects additional versions.

Risk and Exploitability

The CVSS base score of 9.4 highlights very high severity, while the EPSS score is unavailable, indicating the publicly known exploit likelihood is unknown but the risk remains high because the vulnerability can be triggered from any host that can reach the router’s web interface. The router’s management pages are normally exposed to the broader network or the Internet, so a remote attacker can send a malicious payload directly. Though the CVE is not yet listed in CISA’s KEV catalog, the absence of an official patch and the remote nature of the attack vector increase the urgency of remediation.

Generated by OpenCVE AI on June 23, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s website for an updated firmware build that addresses the buffer overflow and upgrade the router immediately once a patch is available.
  • Restrict external access to the router’s management interface by placing it behind a VPN, firewall rule, or by enabling the router’s “only local management” option if available.
  • Block or restrict the cgi-bin/cstecgi.cgi endpoint using the router’s firewall or access control settings, ensuring that only trusted internal hosts can reach the login page.

Generated by OpenCVE AI on June 23, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 23 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink ex1200l
Vendors & Products Totolink
Totolink ex1200l

Tue, 23 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 23 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
Description Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as bricking the router. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146_B20201023 but may also affect other versions.
Title Buffer Overflow in Totolink EX1200L router
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Totolink Ex1200l
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-06-23T13:32:50.690Z

Reserved: 2026-05-05T09:40:05.100Z

Link: CVE-2026-44089

cve-icon Vulnrichment

Updated: 2026-06-23T13:32:47.226Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-23T15:15:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow