Executive brief
TOTOLINK EX1200L is a wireless router used to provide internet connectivity in homes and small offices. A flaw in the web management interface allows a remote attacker to crash the router's configuration service by sending a specially crafted network request, causing a denial of service that temporarily disables administrative access to the device.
Technical details
A null pointer dereference vulnerability exists in the setPasswordCfg function of the Password Configuration Handler (/cgi-bin/cstecgi.cgi) in TOTOLINK EX1200L firmware version 9.3.5u.6146_B20201023. The vulnerable code path fails to validate that required JSON fields (password-related parameters) are present before dereferencing them. An attacker can send a POST request to /cgi-bin/cstecgi.cgi containing only the "topicurl" field set to "setPasswordCfg", omitting mandatory password configuration parameters. The missing fields result in NULL pointer dereference when the code attempts string comparison operations, causing an immediate crash (SIGSEGV). No authentication is required; the attack is remotely exploitable over the network and results in denial of service of the web management CGI component.
Affected products
- TOTOLINK EX1200L 9.3.5u.6146_B20201023
Timeline
- 2026-08-17: disclosed: Advisory published on NVD
- 2026-07-01: other: Exploit proof-of-concept publicly disclosed on GitHub