Back to overview

CVE-2026-3301

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Metadata

CVE ID
CVE-2026-3301
State
PUBLISHED
Assigner
VulDB
Reserved
2026-02-26 20:33 UTC
Published
2026-02-27 05:32 UTC
Last updated
2026-02-27 18:53 UTC
Primary CWE
CWE-78
OS Command Injection
Vendor / Product
Totolink / N300RH
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Totolink N300RH 6.1c.1353_B20190305
Weakness (CWE)
CWESourceDescription
CWE-77 cna Command Injection
CWE-78 cna OS Command Injection
CVSS scores (4)
ScoreSeverityVersionSourceVector
10.0 N/D 2.0 cna AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
9.8 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
References (5)
Back to overview