SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79911

CRITICAL · CVSS 10 EPSS 0.64% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability exists in the CGI Handler of TOTOLINK N600R firmware version 4.3.0cu.7647_B20210106, specifically within the setSystemConfig function. This critical flaw allows remote attackers to manipulate the Hostname argument, potentially leading to arbitrary code execution. Organizations using this router model should prioritize patching or mitigating this vulnerability to prevent exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79911
Severity
CRITICAL
CVSS
10
EPSS
0.64%

Original NVD Description

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.