All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-3301
HIGHpublished 2026-02-27 06:18 UTC · 5 months ago · modified 2026-06-17 10:43 UTC
8.9
CVSS / 10
// description
A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
// weaknesses (CWE)
- CWE-77
- CWE-78