CVE-2026-79912

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 23:17

Updated : 2026-08-26 16:19


NVD link : CVE-2026-79912

Mitre link : CVE-2026-79912

CVE.ORG link : CVE-2026-79912


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')