CVE-2026-82616
9.9TOTOLINK · NR1800X
A stack-based buffer overflow in the setUploadSetting function of the TOTOLINK NR1800X allows remote attackers to execute arbitrary code via the FileName argument.
Executive summary
A critical stack-based buffer overflow vulnerability in the TOTOLINK NR1800X router allows remote, authenticated attackers to achieve arbitrary code execution.
Vulnerability
This vulnerability is a stack-based buffer overflow occurring within the setUploadSetting function of the /cgi-bin/cstecgi.cgi script. An attacker with low-level privileges can trigger this memory corruption by sending a crafted request containing a malicious FileName parameter.
Business impact
The ability to execute arbitrary code remotely poses a severe risk to organizational infrastructure, as attackers could gain full control over the router, intercept network traffic, or pivot into internal network segments. Given the critical CVSS score of 9.9, this vulnerability represents an immediate threat to the integrity and confidentiality of any network utilizing the affected hardware.
Remediation
Immediate Action: Update the TOTOLINK NR1800X firmware to the latest available version provided by the manufacturer to patch the buffer overflow vulnerability.
Proactive Monitoring: Review web access logs for anomalous traffic directed at /cgi-bin/cstecgi.cgi, particularly requests containing unusually long or malformed FileName arguments.
Compensating Controls: Implement WAF rules to inspect and block requests to the cstecgi.cgi endpoint that exceed expected parameter lengths or contain suspicious character patterns.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept document exists and is attributed to the research write-up referenced by the CVE record.
Analyst recommendation
Due to the critical nature of this buffer overflow and the availability of a public proof-of-concept, users must prioritize patching their TOTOLINK NR1800X devices immediately. Organizations that cannot update immediately should restrict administrative access to the affected cstecgi.cgi interface to trusted internal management networks to reduce the attack surface.
More TOTOLINK CVEs
Sources
Originally found and disclosed by 577488768 (VulDB User), per the CVE Program record.
- VDB-397117 | TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow Vulnerability database entry
- VDB-397117 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-82616 | CVE Analysis and Report Third-party advisory
- Submit #892941 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- totolink.net