Totolink NR1800X Buffer Overflow Vulnerability in POST Request Handler

Vulnerability

A buffer overflow vulnerability has been identified in the Totolink NR1800X router, specifically in the firmware version 9.1.0u.6279_B20210910. The issue arises in the POST request handler within the 'setWizardCfg' function of the '/cgi-bin/cstecgi.cgi' file. The vulnerability can be exploited remotely by manipulating the 'ssid' parameter, leading to a buffer overflow condition.

Impact

Exploitation of this vulnerability causes a buffer overflow, which can commonly lead to arbitrary code execution or causing the device to crash.

Added: Jan 22, 2026, 3:21 PM
Updated: Jan 22, 2026, 3:21 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
5.0
exploitability
8.1
remediation
0.0
relevance
2.3
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.