CVE-2026-1156

HIGH

Totolink Lr350 Firmware - Memory Corruption

Title source: rule
STIX 2.1

Description

A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 8.8
EPSS 0.0016
EPSS Percentile 36.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
totolink/lr350_firmware 9.3.5u.6369_b20220309
Published Jan 19, 2026
Tracked Since Feb 18, 2026