PT-2026-36623 · Totolink · N300Rh

Xuanyu

·

Published

2026-05-02

·

Updated

2026-05-02

·

CVE-2026-7633

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
A vulnerability was identified in Totolink N300RH 6.1c.1353 B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-7633

Affected Products

N300Rh