Executive brief
TOTOLINK EX1200L is a wireless router used in home and small office networks. A vulnerability in its web management interface allows a remote attacker to send a specially crafted request that causes the router's web administration service to crash, resulting in denial of service and temporary loss of management access until the device is rebooted.
Technical details
A null pointer dereference vulnerability exists in the setWizardCfg function within the /cgi-bin/cstecgi.cgi CGI binary. The vulnerability occurs when a POST request is sent with incomplete JSON parameters—specifically, providing only the "topicurl" field while omitting required wizard configuration fields. The missing fields propagate as NULL through the parameter handling and string-processing logic, eventually being dereferenced in libc strcoll(), triggering a SIGSEGV crash. The vulnerability is remotely exploitable over the network without authentication. An attacker can reliably crash the cstecgi.cgi process, denying access to the router's web management interface.
Affected products
- TOTOLINK EX1200L 9.3.5u.6146_B20201023
Timeline
- 2026-07-01: disclosed: PoC published on GitHub
- 2026-08-17: advisory: CVE-2026-75013 published