Article

    Cyber News / Article / Vulnerability in Totolink EX1200L router software

    Vulnerability in Totolink EX1200L router software
    CE
    CERT Polska-2026-06-23

    Vulnerability in Totolink EX1200L router software

    CERT Polska has received a report about vulnerability in Totolink EX1200L router software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-44089: Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality incgi-bin/cstecgi.cgiendpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows an unauthenticated attacker to perform actions as root including reading and editing data, as well as bricking the router.

    Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146_B20201023 but may also affect other versions.

    We thank Franciszek Malek for the responsible vulnerability report.

    Original source