9.4
CRITICAL CVSS 4.0
CVE-2026-44089
Buffer Overflow in Totolink EX1200L router
Description

Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as bricking the router. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146_B20201023 but may also affect other versions.

INFO

Published Date :

June 23, 2026, 12:08 p.m.

Last Modified :

June 23, 2026, 12:08 p.m.

Remotely Exploit :

No

Source :

CERT-PL
Affected Products

The following products are affected by CVE-2026-44089 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Totolink ex1200l
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 4.0 CRITICAL 4bb8329e-dd38-46c1-aafb-9bf32bcb93c6
CVSS 4.0 CRITICAL [email protected]
Solution
Address buffer overflow by applying firmware updates from the vendor.
  • Update router firmware to the latest version.
  • Avoid using the login functionality.
  • Contact vendor for patch information.
  • Replace the affected device if possible.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-44089 vulnerability anywhere in the article.

  • cert.pl
Vulnerability in Totolink EX1200L router software

Vulnerability in Totolink EX1200L router software CVE ID CVE-2026-44089 Publication date 23 June 2026 Vendor Totolink Product EX1200L Vulnerable versions 9.3.5u.6146_B20201023 Vulnerability type (CWE) ... Read more

Published Date: Jun 23, 2026 (4 hours, 45 minutes ago)
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.