CVE-2026-79912: Totolink n600r

High severity, CVSS 8.3. EPSS: 2.1% chance of exploitation in the next 30 days.

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.

Affected products

  • Totolink n600r: version 4.3.0cu.7647_B20210106 only

Published 2026-08-25. Last modified 2026-08-26.