CERT Polska disclosed CVE-2026-44089, a stack-based buffer overflow in the Totolink EX1200L router that affects the login functionality of the cgi-bin/cstecgi.cgi endpoint. The flaw can be triggered without authentication and may allow an attacker to crash the service or achieve remote code execution, potentially gaining root-level control of the device.
The vulnerability was confirmed in firmware version 9.3.5u.6146_B20201023, and CERT Polska warned that other versions may also be affected because attempts to contact the vendor were unsuccessful. Successful exploitation could let an attacker read or modify data or even brick the router, and the issue was credited to researcher Franciszek Malek in the responsible disclosure report.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
CERT Polska disclosed CVE-2026-44089, a stack-based buffer overflow in the login functionality of the cgi-bin/cstecgi.cgi endpoint affecting Totolink EX1200L router software. The flaw was confirmed in firmware version 9.3.5u.6146_B20201023 and could allow unauthenticated attackers to crash the program or achieve remote code execution as root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecvefeed.io
Open sourcecert.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.