CVE-2026-1158

HIGH

Totolink LR350 9.3.5u.6369_B20220309 - Buffer Overflow via setWizardCfg SSID Parameter

Title source: llm
STIX 2.1

Description

A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.341752
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.341752
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.735728
Product product
https://www.totolink.net/

Scores

CVSS v3 8.8
EPSS 0.0063
EPSS Percentile 45.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
totolink/lr350_firmware 9.3.5u.6369_b20220309
Published Jan 19, 2026
Tracked Since Feb 18, 2026