Description
A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insufficiently random values. It is possible to launch the attack remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used.
Published: 2026-08-30
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the loginAuth function of the authentication handler allows an attacker to generate insufficiently random authentication tokens, making them predictable. This vulnerability enables remote attackers to forge valid login credentials and obtain unauthorized access to the device. It is tied to issues of limited entropy and weak cryptographic practices, as noted by CWE-310 and CWE-330.

Affected Systems

The vulnerability is specific to TOTOLINK N600R routers running firmware 4.3.0cu.7866_B20220506. No other affected versions are listed in the available data, so the risk applies to devices hosting that exact build.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. Nevertheless, the attack is possible remotely, requires relatively high complexity, and is considered difficult to exploit, but the potential impact of authentication bypass makes it a concern for operators.

Generated by OpenCVE AI on August 30, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TOTOLINK N600R firmware to the latest release that fixes the predictable token issue.
  • If a firmware update is unavailable, disable external access to the authentication API or restrict login traffic to trusted networks.
  • Validate that authentication tokens are generated with sufficient entropy by testing login sessions for predictability.

Generated by OpenCVE AI on August 30, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink n600r
Vendors & Products Totolink n600r

Sun, 30 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insufficiently random values. It is possible to launch the attack remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used.
Title TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
First Time appeared Totolink
Totolink n600r Firmware
Weaknesses CWE-310
CWE-330
CPEs cpe:2.3:o:totolink:n600r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink n600r Firmware
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Totolink N600r N600r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-30T17:30:10.581Z

Reserved: 2026-08-29T18:54:51.440Z

Link: CVE-2026-82555

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T18:17:00.380

Modified: 2026-08-30T18:17:00.380

Link: CVE-2026-82555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T18:30:16Z

Weaknesses