CVE-2026-82555
TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insufficiently random values. It is possible to launch the attack remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used.
| CWE | CWE-330 CWE-310 |
| Vendor | totolink |
| Product | n600r |
| Published | Aug 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for totolink n600r
Be the first to know when new low vulnerabilities affecting totolink n600r are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
TOTOLINK / N600R
4.3.0cu.7866_B20220506
References
vuldb.com: https://vuldb.com/vuln/397071 vuldb.com: https://vuldb.com/vuln/397071/cti vuldb.com: https://vuldb.com/cve/CVE-2026-82555 vuldb.com: https://vuldb.com/submit/891698 github.com: https://github.com/b1uerry/cves/tree/main/TOTOLINK/N600R/TOTOLINK_N600R_predictable-token github.com: https://github.com/b1uerry/cves/blob/main/TOTOLINK/N600R/TOTOLINK_N600R_predictable-token/poc.py totolink.net: https://www.totolink.net/
Credits
๐ bluerry (VulDB User)