← back
CVE-2026-0731

TOTOLINK WA1200 HTTP Request cstecgi.cgi null pointer dereference

CVSS 6.9 MEDIUMEPSS 0.6%CWE-404CWE-476
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been found in TOTOLINK WA1200 5.9c.2914. The impacted element is an unknown function of the file cstecgi.cgi of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
TOTOLINK · WA1200

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →