VendorsTOTOLINKa3600r_firmware5.9c.4959
Vulnerabilities

TOTOLINK A3600R Firmware 4.1.2cu.5182 B20201102 5.9c.4959

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2026-31027
TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary code execution or denial of service.
Published 2026-04-01 · Analyzed
9.8EPSS 0.016
CVE-2026-1686
Totolink A3600R app.so setAppEasyWizardConfig buffer overflow
Published 2026-01-30 · Analyzed
9.0EPSS 0.007