Junglewise Threat Intelligence

CVE-2026-6168: TOTOLINK A7000R stack overflow in setWiFiEasyGuestCfg

CVE-2026-6168 · Severity: high · CVSS 8.8 · Published 2026-04-13

Vendors: TOTOLINK.

Executive brief

A security vulnerability exists in the TOTOLINK A7000R wireless router. This flaw allows an attacker to send specially crafted data to the device's management interface, potentially leading to a complete system takeover or service disruption. If exploited, an attacker could gain unauthorized control over the router, intercept network traffic, or disable internet connectivity for the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the TOTOLINK A7000R router firmware up to version 9.1.0u.6115. The flaw is located within the 'setWiFiEasyGuestCfg' function in the '/cgi-bin/cstecgi.cgi' component. An attacker can trigger the overflow by manipulating the 'ssid5g' argument during a request. This is a remote attack that requires low privileges (authenticated user) and no user interaction. Successful exploitation can lead to arbitrary code execution or a denial-of-service (DoS) condition. Proof-of-concept exploit code has been published.

Affected products

  • TOTOLINK A7000R up to 9.1.0u.6115

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory

References