CVE-2026-6158
HIGHTotolink N300RH upgrade.so setUpgradeUboot os command injection
Title source: cnaDescription
A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Scores
CVSS v3
7.3
EPSS
0.0486
EPSS Percentile
89.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-77
CWE-78
Status
published
Products (1)
Totolink/N300RH
6.1c.1353_B20190305
Published
Apr 13, 2026
Tracked Since
Apr 13, 2026