PT-2026-32259 · Totolink · N300Rh

Xuanyu

·

Published

2026-04-13

·

Updated

2026-04-29

·

CVE-2026-6158

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Totolink N300RH version 6.1c.1353 B20190305
Description A flaw in the setUpgradeUboot() function within the upgrade.so file allows for remote OS command injection. This occurs due to improper manipulation of the FileName argument, which can be exploited to execute arbitrary operating system commands on the device.
Recommendations Update Totolink N300RH version 6.1c.1353 B20190305 to a patched version. Isolate affected devices from the network to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6158

Affected Products

N300Rh