OS Command Injection in Totolink N300RH Web Management Interface
CVE-2026-9543
Key Information:
Badges
What is CVE-2026-9543?
A vulnerability exists in the Totolink N300RH Web Management Interface related to the function setPasswordCfg within the cgi-bin/cstecgi.cgi file. This vulnerability allows for remote execution of OS commands due to improper handling of the admpass argument. Attackers can exploit this flaw to execute arbitrary commands, posing a significant security risk to devices running this version. Given the public disclosure of the exploit, users are advised to take immediate action to secure their systems.
Affected Version(s)
N300RH 6.1c.1353_B20190305
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
