Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-36841 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-04-29 |
| Vendor | TOTOLINK |
| Product | N200RE |
| CVSS Score | 9.8 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.
Required Actions
Check TOTOLINK’s support site for a firmware fix and update the device without delay. Until a patch is available, disable WAN-side remote management and restrict admin panel access to trusted internal IPs only. Monitor logs for unusual requests targeting formMapDelDevice with suspicious macstr/bandstr values.
Who Is Affected?
This vulnerability affects N200RE by TOTOLINK. Check whether your organization uses this router and apply the required security actions.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
