Junglewise Threat Intelligence

CVE-2026-75013: TOTOLINK EX1200L null pointer dereference in setWizardCfg

CVE-2026-75013 · Severity: medium · CVSS 6.5 · Published 2026-08-17

Technologies: TOTOLINK EX1200L. Vendors: TOTOLINK.

Executive brief

TOTOLINK EX1200L is a wireless router used in home and small office networks. A vulnerability in its web management interface allows a remote attacker to send a specially crafted request that causes the router's web administration service to crash, resulting in denial of service and temporary loss of management access until the device is rebooted.

Technical details

A null pointer dereference vulnerability exists in the setWizardCfg function within the /cgi-bin/cstecgi.cgi CGI binary. The vulnerability occurs when a POST request is sent with incomplete JSON parameters—specifically, providing only the "topicurl" field while omitting required wizard configuration fields. The missing fields propagate as NULL through the parameter handling and string-processing logic, eventually being dereferenced in libc strcoll(), triggering a SIGSEGV crash. The vulnerability is remotely exploitable over the network without authentication. An attacker can reliably crash the cstecgi.cgi process, denying access to the router's web management interface.

Affected products

  • TOTOLINK EX1200L 9.3.5u.6146_B20201023

Timeline

  • 2026-07-01: disclosed: PoC published on GitHub
  • 2026-08-17: advisory: CVE-2026-75013 published

References

Related threats