PT-2026-45136 · Totolink · N300Rh
Luotuo
·
Published
2026-05-30
·
Updated
2026-06-15
·
CVE-2026-10187
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Totolink N300RH version 6.1c.1353 B20190305
Description
A stack-based buffer overflow exists in the Web Management Interface component within the
wireless.so file. The issue occurs in the setWiFiBasicConfig() function when the KeyStr argument is manipulated. This flaw allows a remote attacker to execute arbitrary code.Recommendations
For version 6.1c.1353 B20190305, upgrade to the latest firmware advised by the vendor.
As a temporary mitigation, disable remote management to reduce exposure.
Restrict access to the
setWiFiBasicConfig() function to minimize the risk of exploitation.Exploit
Fix
RCE
Buffer Overflow
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
N300Rh