Vulnerability Description
A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | A3700R Firmware | 9.1.2u.5822_b20200513 |
| Totolink | A3700R | - |
Related Weaknesses (CWE)
References
- https://lavender-bicycle-a5a.notion.site/TOTOLINK-A3700R-setWiFiEasyGuestCfg-2e3ExploitThird Party Advisory
- https://vuldb.com/?ctiid.341735Permissions RequiredVDB Entry
- https://vuldb.com/?id.341735Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.735502Third Party AdvisoryVDB Entry
- https://www.totolink.net/Product
FAQ
What is CVE-2026-1143?
CVE-2026-1143 is a vulnerability with a CVSS score of 8.8 (HIGH). A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument ssid c...
How severe is CVE-2026-1143?
CVE-2026-1143 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-1143?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink A3700R Firmware, Totolink A3700R.