OS Command Injection Vulnerability in Totolink N300RH Web Management Interface
CVE-2026-3301
Key Information:
Badges
What is CVE-2026-3301?
A vulnerability has been identified in the web management interface of the Totolink N300RH model version 6.1c.1353_B20190305. This flaw arises from improper handling of the 'webWlanIdx' parameter in the 'setWebWlanIdx' function found in '/cgi-bin/cstecgi.cgi'. Remote attackers can exploit this oversight to execute arbitrary operating system commands on the affected device, posing a significant security risk. As the exploit details have been released publicly, organizations using this model are advised to take necessary precautions and update their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
N300RH 6.1c.1353_B20190305
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
