PT-2026-32259 · Totolink · N300Rh

Xuanyu

·

Published

2026-04-13

·

Updated

2026-04-13

·

CVE-2026-6158

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
A flaw has been found in Totolink N300RH 6.1c.1353 B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6158

Affected Products

N300Rh