CVE-2026-44089: Buffer Overflow in Totolink EX1200L router
Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as bricking the router.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146B20201023 but may also affect other versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote/WAN access to the CGI login endpoint (cgi-bin/cstecgi.cgi) in the device management configuration or administration UI so the login functionality is not reachable from untrusted networks.
Totolink EX1200L web admin (cgi-bin/cstecgi.cgi) access_from_wan = disabled - Compensating control
Block external/WAN access to the login CGI endpoint /cgi-bin/cstecgi.cgi at network edge devices (firewall/ACL) and permit access only from trusted management IPs.
- Operational
Inventory all Totolink EX1200L devices and identify any running firmware version 9.3.5u.6146_B20201023. Isolate identified devices from untrusted networks (remove WAN access or place on a quarantined VLAN) until a vendor fix or other remediation is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44089?
CVE-2026-44089 has a risk rating of 89, indicating a high severity vulnerability.
How do I fix CVE-2026-44089?
To fix CVE-2026-44089, update the firmware of the Totolink EX1200L router to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2026-44089?
CVE-2026-44089 is a Buffer Overflow vulnerability found in the login functionality of the Totolink EX1200L router.
What can an attacker do if they exploit CVE-2026-44089?
If exploited, CVE-2026-44089 allows an attacker to execute code remotely and perform actions as the root user.
In which component of the Totolink EX1200L is CVE-2026-44089 found?
CVE-2026-44089 is found in the cgi-bin/cstecgi.cgi endpoint of the Totolink EX1200L router.