PT-2026-45136 · Totolink · N300Rh

Luotuo

·

Published

2026-05-30

·

Updated

2026-06-15

·

CVE-2026-10187

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Totolink N300RH version 6.1c.1353 B20190305
Description A stack-based buffer overflow exists in the Web Management Interface component within the wireless.so file. The issue occurs in the setWiFiBasicConfig() function when the KeyStr argument is manipulated. This flaw allows a remote attacker to execute arbitrary code.
Recommendations For version 6.1c.1353 B20190305, upgrade to the latest firmware advised by the vendor. As a temporary mitigation, disable remote management to reduce exposure. Restrict access to the setWiFiBasicConfig() function to minimize the risk of exploitation.

Exploit

Fix

RCE

Buffer Overflow

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-07644
CVE-2026-10187

Affected Products

N300Rh