A vulnerability was found in TOTOLINK A3600R 5.9c.4959. It has been declared as critical. Affected by this issue is the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument rootSsid results in buffer overflow.

This vulnerability is identified as CVE-2026-31027. The attack can be executed remotely. There is not any exploit available.