Buffer Overflow Vulnerability in Totolink Router Software
CVE-2026-1157
Key Information:
Badges
What is CVE-2026-1157?
A vulnerability in the Totolink LR350 router version 9.3.5u.6369_B20220309 has been discovered, specifically within the setWiFiEasyCfg function of the /cgi-bin/cstecgi.cgi file. This flaw allows an attacker to manipulate the 'ssid' argument, resulting in a buffer overflow condition. The exploit can be executed remotely, making this vulnerability particularly concerning. Publicly available exploit techniques increase the risk of compromise, underlining the need for immediate remediation.
Affected Version(s)
LR350 9.3.5u.6369_B20220309
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
