A critical, publicly disclosed stack-based buffer overflow exists in TOTOLINK N600R routers (firmware 4.3.0cu.7647_B20210106) via the Hostname parameter in the setSystemConfig function of cstecgi.cgi. The flaw is remotely exploitable without authentication and carries a maximum CVSS score of 10.0, allowing attackers to potentially achieve remote code execution on affected devices.
Updated Aug 27, 2026 · CVSS 10