| CVE ID | CVE-2026-44089 |
| Publication date | 23 June 2026 |
| Vendor | Totolink |
| Product | EX1200L |
| Vulnerable versions | 9.3.5u.6146_B20201023 |
| Vulnerability type (CWE) | Stack-based Buffer Overflow (CWE-121) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Totolink EX1200L router software and participated in coordination of its disclosure.
The vulnerability CVE-2026-44089: Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows an unauthenticated attacker to perform actions as root including reading and editing data, as well as bricking the router.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 9.3.5u.6146_B20201023 but may also affect other versions.
Credits
We thank Franciszek Malek for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.