Back to overview

CVE-2026-44089

CRITICAL
9.4
CVSS 4.0
Description
Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as bricking the router. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146_B20201023 but may also affect other versions.

Metadata

CVE ID
CVE-2026-44089
State
PUBLISHED
Assigner
CERT-PL
Reserved
2026-05-05 09:40 UTC
Published
2026-06-23 12:08 UTC
Last updated
2026-06-23 13:32 UTC
Primary CWE
CWE-121
CWE-121 Stack-based Buffer Overflow
Vendor / Product
Totolink / EX1200L
Sources
cve.org  ·  NVD

Severity & Metrics

9.4 CRITICAL CVSS 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Totolink EX1200L 9.3.5u.6146_B20201023
Weakness (CWE)
CWESourceDescription
CWE-121 cna CWE-121 Stack-based Buffer Overflow
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.4 CRITICAL 4.0 cna CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Back to overview