Junglewise Threat Intelligence

CVE-2026-44089: Totolink EX1200L buffer overflow in cstecgi.cgi login

CVE-2026-44089 · Severity: info · CVSS 9.4 · Published 2026-06-23

Technologies: TOTOLINK EX1200L. Vendors: TOTOLINK.

Executive brief

The Totolink EX1200L router, a device used to extend wireless network coverage, contains a critical security flaw in its login interface. An attacker on the same network can exploit this to crash the device or take full control of it without needing a password. This could lead to the theft of data passing through the router, permanent damage to the hardware (bricking), or unauthorized access to other devices on the network.

Technical details

A stack-based buffer overflow (CWE-121) exists in the Totolink EX1200L router within the 'cgi-bin/cstecgi.cgi' endpoint. The vulnerability is located in the login functionality and can be triggered by an unauthenticated attacker with network access to the device's management interface (typically via the adjacent network). Successful exploitation allows the attacker to execute arbitrary code with root privileges, leading to full system compromise, data interception, or permanent denial of service (bricking). The vulnerability has been confirmed in firmware version 9.3.5u.6146_B20201023; however, as vendor contact attempts were unsuccessful, a patch is not currently available.

Affected products

  • Totolink EX1200L 9.3.5u.6146_B20201023

Timeline

  • 2026-06-23: advisory: Advisory published by CERT.PL
  • 2026-06-23: disclosed: CVE-2026-44089 published to NVD

References

Related threats