TOTOLINK NR1800X setUploadSetting Stack-Based Buffer Overflow (CVE-2026-82616)

Release Date: 31st August 2026 (Added 9 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and members of the general public that use a TOTOLINK NR1800X 5G/LTE Wi-Fi 6 router. This alert is intended to be understood by both technical and general readers.

What is it?

CVE-2026-82616 is a critical stack-based buffer overflow in the setUploadSetting function of the file /cgi-bin/cstecgi.cgi on the TOTOLINK NR1800X, a mass-market, SIM-card-based 5G/LTE Wi-Fi 6 router sold through general electronics retailers internationally (including Amazon and multiple European and African online retailers), with no dependency on a specific local ISP or fixed-line service – any individual with a compatible mobile SIM can purchase and deploy one.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-82616
  2. https://radar.offseq.com/threat/cve-2026-82616-stack-based-buffer-overflow-in-totolink-nr1800x-6c42a25faadab882