Junglewise Threat Intelligence

CVE-2026-82616: TOTOLINK NR1800X stack-based buffer overflow in setUploadSetting

CVE-2026-82616 · Severity: critical · CVSS 9.9 · Published 2026-08-31

Technologies: TOTOLINK Nr1800x. Vendors: TOTOLINK.

Executive brief

TOTOLINK NR1800X is a network router used in home and small business environments. A stack-based buffer overflow vulnerability in the web administration interface allows an attacker to send a specially crafted request with an oversized filename parameter, potentially leading to remote code execution and complete compromise of the device. The exploit has been publicly disclosed and proof-of-concept code is available.

Technical details

A stack-based buffer overflow exists in the setUploadSetting function of the /cgi-bin/cstecgi.cgi endpoint. The vulnerability is triggered by insufficient bounds checking on the FileName parameter, which allows an attacker to overwrite stack memory by providing an excessively long filename. The attack is remotely exploitable without authentication requirements and can lead to arbitrary code execution with device privileges. A public proof-of-concept has been released, increasing the risk of active exploitation.

Affected products

  • TOTOLINK NR1800X 9.1.0u.6681_B20230703

Timeline

  • 2026-08-31: disclosed
  • other: Public exploit proof-of-concept released

References

Related threats