CVE-2026-31027Disclosure(totolink / a3600r)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch totolink a3600r systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary code execution or denial of service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • a3600r
  • a3600r_firmware

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
a3600ra3600r_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-02: 2Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-02: 204-02
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CosmicBytez@CosmicBytez
    Patch

    Security Advisory: CVE-2026-31027: TOTOlink A3600R Buffer Overflow in setAppEasyWizardConfig https://labs.cosmicbytez.ca/security/cve-2026-31027 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    A security advisory announces a buffer overflow vulnerability (CVE-2026-31027) in the TOTOlink A3600R firmware, with indications that a patch or mitigation is available.

    0000041
    1 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-31027: CRITICAL] Critical buffer overflow vulnerability discovered in TOTOlink A3600R v5.9c.4959. Attackers can exploit setAppEasyWizardConfig interface to trigger buffer overflow, leading to code ...#cve,CVE-2026-31027,#cybersecurity https://cvefind.com/CVE-2026-31027

    Post summary

    A critical buffer overflow flaw was discovered in TOTOlink A3600R firmware, allowing attackers to trigger code execution via the setAppEasyWizardConfig interface. No PoC, exploit code, patch, or active exploitation reports are provided.

    0000034
    617 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtotolinka3600r---
OStotolinka3600r_firmware5.9c.4959--

Explore more