CVE-2026-4976
HIGHTotolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow
Title source: cnaDescription
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
References (5)
Scores
CVSS v3
8.8
EPSS
0.0016
EPSS Percentile
36.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-119
CWE-120
Status
published
Products (2)
Totolink/LR350
9.3.5u.6369_B20220309
totolink/lr350_firmware
9.3.5u.6369_b20220309
Published
Mar 27, 2026
Tracked Since
Mar 29, 2026