CVE-2026-44089 Details
Description
Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as bricking the router. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146_B20201023 but may also affect other versions.
A stack-based buffer overflow vulnerability has been identified in the Totolink EX1200L router, specifically in the login functionality of the cgi-bin/cstecgi.cgi endpoint. This vulnerability, confirmed in version 9.3.5u.6146_B20201023, but potentially affecting other versions, could be exploited to cause the program to crash and execute code remotely. Exploitation allows an unauthenticated attacker to perform actions as root, including reading and editing data or bricking the router.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2026/06/CVE-2026-44089 | [email protected] | AdvisoryVendor |
| https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/217/ids/36.html | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Totolink EX1200L | 9.3.5u.6146_B20201023 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion