Executive brief
TOTOLINK NR1800X is a network router used in home and small business environments. A stack-based buffer overflow vulnerability in the web administration interface allows an attacker to send a specially crafted request with an oversized filename parameter, potentially leading to remote code execution and complete compromise of the device. The exploit has been publicly disclosed and proof-of-concept code is available.
Technical details
A stack-based buffer overflow exists in the setUploadSetting function of the /cgi-bin/cstecgi.cgi endpoint. The vulnerability is triggered by insufficient bounds checking on the FileName parameter, which allows an attacker to overwrite stack memory by providing an excessively long filename. The attack is remotely exploitable without authentication requirements and can lead to arbitrary code execution with device privileges. A public proof-of-concept has been released, increasing the risk of active exploitation.
Affected products
- TOTOLINK NR1800X 9.1.0u.6681_B20230703
Timeline
- 2026-08-31: disclosed
- other: Public exploit proof-of-concept released