PT-2026-36745 · Totolink · Wa300

Wxhwxhwxh_Mie

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-7717

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
A vulnerability was determined in Totolink WA300 5.2cu.7112 B20190227. This issue affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executing a manipulation of the argument File can lead to buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-7717

Affected Products

Wa300