Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wgfc-85p2-7526

Опубликовано: 26 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 10

Описание

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

EPSS

Процентиль: 49%
0.00644
Низкий

9.3 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 10
nvd
26 дней назад

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 10
fstec
3 месяца назад

Уязвимость функции setSystemConfig() компонента CGI Handler микропрограммного обеспечения маршрутизаторов Totolink-N600R, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 49%
0.00644
Низкий

9.3 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-119