A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insufficiently random values. It is possible to launch the attack remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used.

Project Subscriptions

Vendors Products
Totolink Subscribe
N600r Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 30 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink n600r
Vendors & Products Totolink n600r

Sun, 30 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insufficiently random values. It is possible to launch the attack remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used.
Title TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
First Time appeared Totolink
Totolink n600r Firmware
Weaknesses CWE-310
CWE-330
CPEs cpe:2.3:o:totolink:n600r_firmware:*:*:*:*:*:*:*:*
Vendors & Products Totolink
Totolink n600r Firmware
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-30T17:30:10.581Z

Reserved: 2026-08-29T18:54:51.440Z

Link: CVE-2026-82555

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T18:17:00.380

Modified: 2026-08-30T18:17:00.380

Link: CVE-2026-82555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T18:30:16Z

Weaknesses