CVE-2026-1328 describes a critical buffer overflow vulnerability in the Totolink NR1800X router, specifically affecting firmware version 9.1.0u.6279_B20210910. This flaw resides within the setWizardCfg function of the /cgi-bin/cstecgi.cgi component, triggered by manipulating the 'ssid' argument in a POST request. Rated with a CVSS score of 8.8 (High), this vulnerability can be exploited remotely with low attack complexity and requires only low privileges, potentially leading to high impact on confidentiality, integrity, and availability. The public availability of exploit code further elevates its risk. While exploit code is publicly available, there is currently no evidence of active exploitation in the wild, nor are there Metasploit or Nuclei modules. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.1.0u.6279_b20210910CPE matchmatch criteria | cpe:2.3:o:totolink:nr1800x_firmware:9.1.0u.6279_b20210910:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.