Executive brief
The Totolink EX1200L router, a device used to extend wireless network coverage, contains a critical security flaw in its login interface. An attacker on the same network can exploit this to crash the device or take full control of it without needing a password. This could lead to the theft of data passing through the router, permanent damage to the hardware (bricking), or unauthorized access to other devices on the network.
Technical details
A stack-based buffer overflow (CWE-121) exists in the Totolink EX1200L router within the 'cgi-bin/cstecgi.cgi' endpoint. The vulnerability is located in the login functionality and can be triggered by an unauthenticated attacker with network access to the device's management interface (typically via the adjacent network). Successful exploitation allows the attacker to execute arbitrary code with root privileges, leading to full system compromise, data interception, or permanent denial of service (bricking). The vulnerability has been confirmed in firmware version 9.3.5u.6146_B20201023; however, as vendor contact attempts were unsuccessful, a patch is not currently available.
Affected products
- Totolink EX1200L 9.3.5u.6146_B20201023
Timeline
- 2026-06-23: advisory: Advisory published by CERT.PL
- 2026-06-23: disclosed: CVE-2026-44089 published to NVD