Buffer Overflow Vulnerability in Totolink LR350 Router
CVE-2026-1158
Key Information:
Badges
What is CVE-2026-1158?
A security flaw exists in the Totolink LR350 router, particularly in the function setWizardCfg within the POST Request Handler component. This vulnerability allows for remote exploitation through a manipulated argument, leading to a buffer overflow. As a result, attackers can potentially compromise the device's integrity. The flaw has been publicly disclosed, highlighting its significance in the realm of cybersecurity, necessitating prompt attention from affected users.
Affected Version(s)
LR350 9.3.5u.6369_B20220309
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
