CVE-2026-79912
8.3TOTOLINK · N600R
A command injection vulnerability exists in the TOTOLINK N600R router, allowing unauthenticated attackers to execute arbitrary commands via the device interface.
Executive summary
A critical command injection vulnerability in TOTOLINK N600R routers allows unauthenticated attackers to gain unauthorized control over the device.
Vulnerability
This is a command injection vulnerability (CWE-77) that occurs due to insufficient input validation. The vulnerability is exploitable by an unauthenticated attacker over the network.
Business impact
With a CVSS score of 8.3, this vulnerability poses a severe risk to network infrastructure. Exploitation allows an attacker to execute arbitrary commands, potentially resulting in full device takeover, interception of network traffic, and lateral movement within the local network.
Remediation
Immediate Action: Check the official TOTOLINK support portal for firmware updates addressing this command injection vulnerability. If no patch is available, isolate the device from the public internet.
Proactive Monitoring: Inspect network traffic for anomalous outbound connections or unauthorized administrative commands originating from the router.
Compensating Controls: Disable remote management interfaces and restrict access to the device management panel to internal, trusted network segments via firewall rules.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept is available via a GitHub repository.
Analyst recommendation
Due to the nature of command injection and the availability of public proof-of-concept code, this vulnerability is highly dangerous. If an official firmware patch is not yet available, organizations must immediately restrict access to the device to mitigate the risk of unauthorized command execution.