What is CVE-2026-75013?
A null pointer dereference vulnerability was found in the setWizardCfg function of the /cgi-bin/cstecgi.cgi file in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This can be exploited remotely. Since a public exploit is available, it is recommended to disconnect the device from the network until a patch is released.
Azərbaycanca: TOTOLINK EX1200L 9.3.5u.6146_B20201023 proqurğusunda `/cgi-bin/cstecgi.cgi` faylındakı setWizardCfg funksiyasında null pointer dereference zəifliyi aşkarlanıb. Bu boşluq uzaqdan istismar edilə bilər. İctimai exploit mövcud olduğu üçün cihazı şəbəkədən ayırmaq və istehsalçıdan yamaq çıxana qədər gözləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-476; shared vendor: TOTOLINK
FAQ2
What should I do with my TOTOLINK EX1200L if it has the CVE-2026-75013 vulnerability until a patch is released?
Since a public exploit is available, it is recommended to disconnect the device from the network immediately.
In which function of the TOTOLINK EX1200L was CVE-2026-75013 discovered?
The vulnerability was found in the setWizardCfg function of the `/cgi-bin/cstecgi.cgi` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.