ZeroHour

CVE-2026-82616

Stack-Based Buffer Overflow in TOTOLINK NR1800X Router setUploadSetting

CVSS 4.0
8.6 high
EPSS
<1%p47
Published
()
Modified
AI analysis

TOTOLINK NR1800X routers running firmware 9.1.0u.6681_B20230703 contain a stack-based buffer overflow (CWE-121) in the setUploadSetting function of the /cgi-bin/cstecgi.cgi endpoint. It is triggered by a remote request that supplies a manipulated or oversized FileName parameter to this CGI handler, overrunning a fixed-size stack buffer; the CVSS 4.0 vector (AV:N, PR:L) indicates the attacker needs network access and only low-privilege (authenticated) access. Successful exploitation corrupts process memory with high impact on confidentiality, integrity, and availability (C:H/VI:H/VA:H), which for a router typically enables control of the device's management process and potentially full device takeover. Operators of TOTOLINK NR1800X routers on the affected firmware build are affected, particularly those whose web management interface is reachable from untrusted networks. Exploit details have been made public per the disclosure, but the flaw is not in CISA KEV and EPSS currently estimates only a ~0.6% probability of exploitation in the next 30 days.

What to do: Check the running firmware version in the router's admin interface; if it is 9.1.0u.6681_B20230703, restrict or firewall the web management interface (cstecgi.cgi) so it is not reachable from the WAN or other untrusted networks, and limit the number of low-privilege admin accounts. Watch TOTOLINK advisories for a fixed firmware release and upgrade as soon as one is published (no fixed version is identified in the available data). Monitor for exploitation attempts against cstecgi.cgi, as exploit details are public.

Affected
TOTOLINK NR1800X9.1.0u.6681_B20230703 (the firmware build cited in the disclosure; whether other firmware versions are affected is not stated in the data)
Estimated exposure
unknown (no public install-base or internet-exposure scan counts are available for this router model) — The NR1800X is a single consumer/SOHO router model from a mid-tier vendor with no published install-base figures or Shodan/Censys-style exposure counts, so the affected population cannot be reliably quantified, and many deployed units…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

Weakness
CWE-119, CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.