File Inclusion Vulnerability in Totolink N300RH Product
CVE-2026-7633
Key Information:
Badges
What is CVE-2026-7633?
A file inclusion vulnerability exists in the Totolink N300RH model affecting version 6.1c.1353_B20190305. Specifically, the function setUploadSetting located in the /cgi-bin/cstecgi.cgi file allows for remote manipulation of the FileName argument. This flaw can be exploited to include unauthorized files from the server, potentially leading to unauthorized access and control over system settings. As the exploit is publicly available, users of this device are at an increased risk of compromise.
Affected Version(s)
N300RH 6.1c.1353_B20190305
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
