Buffer Overflow Vulnerability in Totolink EX1200L Router
CVE-2026-44089

9.4CRITICAL

Key Information:

Vendor

Totolink

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-44089?

The Totolink EX1200L router contains a buffer overflow vulnerability affecting its login functionality via the cgi-bin/cstecgi.cgi endpoint. Exploitation of this flaw may allow attackers to crash the device or execute arbitrary code with root privileges, enabling unauthorized access to sensitive data and even potential device failure. While confirmed in version 9.3.5u.6146_B20201023, other versions may also be impacted due to unsuccessful vendor communication regarding this security issue.

Affected Version(s)

EX1200L 9.3.5u.6146_B20201023

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Franciszek Malek
.