← Back to overview

A stack-based buffer overflow vulnerability has been identified in TOTOLINK NR1800X firmware version 9.1.0u.6681_B20230703. The vulnerability exists in the setUploadSetting function within the /cgi-bin/cstecgi.cgi file. Attackers can exploit this by manipulating the FileName argument to trigger a stack-based buffer overflow. The attack vector is remote, requiring no physical access to the device. A public exploit has already been released, increasing the risk of active exploitation. TOTOLINK NR1800X is a network router/modem device, making this vulnerability particularly impactful for network infrastructure security. The vulnerability has been assigned CVE-2026-82616 and is tracked in VulDB. Organizations using the affected firmware version should monitor for patches from TOTOLINK. The public availability of the exploit significantly raises the urgency of remediation.

Affected products

  • TOTOLINK NR1800X 9.1.0u.6681_B20230703

Related CVE's

  • CVE-2026-82616

Categories

  • Mobile & IoT
  • Network Infrastructure