CVE-2026-79911
10.0TOTOLINK · N600R
The TOTOLINK N600R router contains a stack-based buffer overflow in the setSystemConfig function, allowing remote attackers to execute arbitrary code via a crafted Hostname parameter.
Executive summary
A critical stack-based buffer overflow in the TOTOLINK N600R router allows remote attackers to compromise the device via malicious input.
Vulnerability
The setSystemConfig function in the CGI handler improperly validates the Hostname argument, leading to a stack-based buffer overflow. This vulnerability is reachable remotely without authentication.
Business impact
A successful exploit results in total compromise of the network device, potentially allowing an attacker to intercept traffic, modify configurations, or pivot into the internal network. Given the CVSS score of 10.0, this represents the highest level of risk to organizational infrastructure.
Remediation
Immediate Action: Check the official TOTOLINK support portal for firmware updates and apply them immediately if available.
Proactive Monitoring: Monitor network traffic for anomalous behavior or unauthorized configuration changes originating from the management interface.
Compensating Controls: Restrict access to the router management interface to trusted administrative IP addresses only, and disable remote management features where possible.
Exploitation status
Public Exploit Available: Yes, a technical analysis and proof-of-concept documentation exist via GitHub.
Analyst recommendation
Due to the severity of this remote code execution vulnerability and the availability of public exploit information, immediate action is required. If no firmware patch is available, isolate the device from the public internet immediately to prevent exploitation.