CVE-2026-79911
CRITICAL(10.0)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- CVSS 10 — Kritisch
EPSS-Score
1.1%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
10
Technische Schwere
SecBoard-Einordnung
CVE-2026-79911 betrifft den TOTOLINK N600R Router, Version 4.3.0cu.7647_B20210106. Es handelt sich um einen Stack-basierten Buffer Overflow in der Funktion setSystemConfig des CGI Handlers, der durch Manipulation des Hostname-Arguments ausgelöst wird. Diese Schwachstelle ermöglicht die Remotecodeausführung auf dem Gerät. Die Ausnutzung kann zu einem vollständigen Verlust der Systemkontrolle führen.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.